Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Secure #14

Closed
ghost opened this issue May 12, 2020 · 9 comments
Closed

Secure #14

ghost opened this issue May 12, 2020 · 9 comments

Comments

@ghost
Copy link

ghost commented May 12, 2020

Is it secure to transfer data with this plugin?

@ghost
Copy link
Author

ghost commented May 12, 2020

@ATechAdventurer Do you know sth. about this topic?

@phybros
Copy link
Collaborator

phybros commented May 12, 2020

Hi @kial1 no it's not.

As per https://github.com/phybros/servertap/blob/master/README.md

This plugin is under development and is not ready for real usage yet.

@phybros phybros closed this as completed May 12, 2020
@ghost
Copy link
Author

ghost commented May 12, 2020

Will you implement https support?

@phybros
Copy link
Collaborator

phybros commented May 12, 2020

Not for a while. My first instinct is that you should run this behind a reverse proxy such as nginx, apache2 or haproxy and have that do the TLS termination for you.

@ghost
Copy link
Author

ghost commented May 12, 2020

Is it secure when only one ip adress can access the port?

@phybros
Copy link
Collaborator

phybros commented May 12, 2020

If you have a firewall in front of servertap that is capable of whitelisting IPs, that could work. I wouldn't rely on IP whitelisting in the long-term though.

@ghost
Copy link
Author

ghost commented May 12, 2020

I wouldn't rely on IP whitelisting in the long-term though.

I want to keep the api private, why do you think so?

@phybros
Copy link
Collaborator

phybros commented May 12, 2020

IP Whitelisting is good if you want to keep it private, but the traffic is still unencrypted and there is no Authentication (see #6). These are 3 separate topics

@ghost
Copy link
Author

ghost commented May 12, 2020

I am using cloudflare but when I change the port from servertap to a https port it doesn't work (i know that it isn't supported now). But isn't it really important for the plugin to have ssl btw. https?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant