Hacker News new | ask | show | jobs
by x1798DE 3427 days ago
What about provisioning other, non-securedrop stuff on that subdomain, and not calling it "securedrop"? Seems like that's better than nothing:

misc.mydomain.com/securedrop misc.mydomain.com/pacman-game misc.mydomain.com/portraits-of-frieda-kahlo

Ideally you'd leave it at the top level since obviously whatever other random junk you put on the subdomain will be lower-traffic than the main domain, but at least here there's plausible deniability (I was just clicking on an easter egg that played pac-man!)