Skip to content

Use TLS / HSTS for the site, discourse, etc. #17914

Closed
@annevk

Description

@annevk

That way active attackers cannot spoof download links for software from insecure pages and credentials cannot be leaked passively from the forums.

https://wiki.whatwg.org/wiki/TLS has more reasons if those are not sufficient.

Endgame: http://hstspreload.appspot.com/

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions