Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

piwik.org https implementation is insecure #8233

Closed
thomaszbz opened this issue Jun 26, 2015 · 2 comments
Closed

piwik.org https implementation is insecure #8233

thomaszbz opened this issue Jun 26, 2015 · 2 comments
Labels
duplicate For issues that already existed in our issue tracker and were reported previously.

Comments

@thomaszbz
Copy link

You have a C rating at qualys. Please check out https://www.ssllabs.com/ssltest/analyze.html?d=piwik.org&hideResults=on

This looks totally insecure to me. Kick your hoster if he does not improve this.

Your certificate is valid 6 weeks from now. It would be a good idea to not only get a secure certificate but also a secure HTTPS implementation.

With Debian 8 stable, you'd easily get an A+ rating from qualys.

I strongly encourage to use the https-only strategy. User's won't even notice anything if it's done right.

Keep in mind that documentation can be security related (e.g. installation steps #8232) because MITM-compromised documentation will let users do insecure stuff.

@sgiehl sgiehl added the duplicate For issues that already existed in our issue tracker and were reported previously. label Jun 29, 2015
@sgiehl
Copy link
Member

sgiehl commented Jun 29, 2015

See #7598 and isvsecwatch/httpstracker#22

@sgiehl sgiehl closed this as completed Jun 29, 2015
@thomaszbz
Copy link
Author

I'd never give this proxy-service a private key...

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
duplicate For issues that already existed in our issue tracker and were reported previously.
Projects
None yet
Development

No branches or pull requests

2 participants