Hacker News new | ask | show | jobs
by antocv 4085 days ago
I, for one, aint playin with anything you build. You aint coming close to having sudo on any of my machines if I can help it.

This shit with "enable security" as after-thought has to stop.

1 comments

I agree. Basically makes me distrust the whole thing inside and out; who knows what other bs engineering practices were used in non visible parts of the stack? Shipping is great, but please don't ship insecure stuff as a product you want customers to use. Please.
We are enabled HTTPS. THX for your comments.

Next: installer update. Give us few minutes.

Great. Glad to see you're taking this seriously and hopefully it is a good lesson learned for the future!
Here: https://www.ssllabs.com/ssltest/analyze.html?d=app.lastbacke...

Overall Rating: C This server is vulnerable to the POODLE attack. If possible, disable SSL 3 to mitigate. Grade capped to C.