Hacker News new | ask | show | jobs
by pharrington 242 days ago
Install your non-self generated SSL certificate correctly, and make sure users can't upload arbitrary content to your domain.