|
|
|
|
|
by ericselin
245 days ago
|
|
Author here. What kind of security negligence are you referring to? What would be a specific attack vector that I left open? Regarding the PSL - and I can't believe I'm writing this again: you cannot get on there before your service is big enough and "the request authentically merits such widespread inclusion"[1]. So it's kind of a chicken and egg situation. Regarding the best practice of hosting user content on a separate domain: this has basically two implications:
1. Cookie scope of my own assets (e.g. dashboard), which one should limit in any case and which I'm of course doing. So this is not an issue.
2. Blacklisting, which is what all of this has been about. I did pay the price here. This has nothing to do with security, though. I'm sorry to be so frank, but you don't know anything about me or my security practices and your claim of negligence is extremely unfounded. [1] https://github.com/publicsuffix/list/wiki/Guidelines#validat... |
|
I am not talking about "security negligence". I am talking about "negligence". The negligence was to not follow standard best practices known for over 20 years which led to disruption in your services.