[Cryptech Tech] Some problems with the repo access

Jakob Schlyter jakob at kirei.se
Fri Feb 14 07:14:20 UTC 2014


Regarding HTTPS, I think we should consider going for a public (webtrust) certificate and, after that, enable strict transport security. Also, doing some serious TLS tweaking (and TLSA records) seems appropriate.

I understand web trust and such may be in conflict with beliefs and goals, but the added value at the current time puts me in favor - at least as long as the target audience of the website is primarily the general public (and not only project participants).


	jakob




More information about the Tech mailing list