Why is the LJ site still not doing HTTPS connections for auth now that it's Digital only? (Does Android too)
Question: Why is the LJ site still not doing HTTPS connections (even if just for login/authentication)? And now that it's an all Digital publication it should be mandatory, don't you think?
I enjoy LJ or wouldn't be a long time subscriber/supporter. Please respect your readers and supporters by protecting their activities with LJ.
For example, you do realize that Forum-like sites are some of the most frequently targeted for being vandalized. PHPBB has been a prime example.
Then there's the fact you have contact information, subscription information, etc. If any one really populates their profile, they've made themselves a target for a greater chance of identity theft. Oh, and if they're dumb enough to use a common password, they deserve to raked over.
Please, do us a favor. Please properly implement https://www.linuxjournal.com . Because right now, if you accept the non-site matching Cert, your homepage says, "It works!" (That's so 1990 and embarrassing.)
Thanks in advance, Mark S.
PS. Don't forget to encrypt or hash our site passwords in your database. You wouldn't want further embarrassment (like the PerlMonks were a few years ago.)
PPS. Make sure your Android App is also using HTTPS please. Mobile connections need SSL too.
Fast/Flexible Linux OS Recovery
On Demand Now
In this live one-hour webinar, learn how to enhance your existing backup strategies for complete disaster recovery preparedness using Storix System Backup Administrator (SBAdmin), a highly flexible full-system recovery solution for UNIX and Linux systems.
Join Linux Journal's Shawn Powers and David Huffman, President/CEO, Storix, Inc.
Free to Linux Journal readers.Register Now!
- Devuan Beta Release
- May 2016 Issue of Linux Journal
- EnterpriseDB's EDB Postgres Advanced Server and EDB Postgres Enterprise Manager
- The US Government and Open-Source Software
- The Humble Hacker?
- The Death of RoboVM
- BitTorrent Inc.'s Sync
- Open-Source Project Secretly Funded by CIA
- New Container Image Standard Promises More Portable Apps
- AdaCore's SPARK Pro
In modern computer systems, privacy and security are mandatory. However, connections from the outside over public networks automatically imply risks. One easily available solution to avoid eavesdroppers’ attempts is SSH. But, its wide adoption during the past 21 years has made it a target for attackers, so hardening your system properly is a must.
Additionally, in highly regulated markets, you must comply with specific operational requirements, proving that you conform to standards and even that you have included new mandatory authentication methods, such as two-factor authentication. In this ebook, I discuss SSH and how to configure and manage it to guarantee that your network is safe, your data is secure and that you comply with relevant regulations.Get the Guide