stormkit-io / app-stormkit-io

Stormkit is an all in one solution for Full Stack Javascript applications.
https://app.stormkit.io
GNU General Public License v3.0
66 stars 8 forks source link

[vuln] subdomain phishing #369

Closed filippofinke closed 2 years ago

filippofinke commented 2 years ago

I think we should find a safe way to tell users when they are on official stormkit services instead of those hosted on behalf of users.

For example I have the domain https://beta.stormkit.io that redirects to my personal site and I think an average user (even a developer) might fall for it thinking it's the original stormkit beta.

I have thought of several solutions:

filippofinke commented 2 years ago

Okay, that was a big fail.

Currently there is already another domain called stormkit.dev for user apps.

svedova commented 2 years ago

@filippofinke maybe a different and shorter domain can remove this confusion. We're working on a v2 for the hosting - guess we can use the new and more different domain name for v2 deployments.