Comment on Nextcloud zero day security

<- View Parent
TechLich@lemmy.world ⁨10⁩ ⁨months⁩ ago

there’s an argument that HTTPS isn’t really required…

Talescale is awesome but you gotta remember that Talescale itself is one of those services (Yikes). Like all applications it’s potentially susceptible to vulnerabilities and exploits so don’t fall into the trap of thinking that anything in your private network is safe because it’s only available through the VPN. “Defence in depth” is a thing and you have nothing to lose from treating your services as though they were public and having multiple layers of security.

The other thing to keep in mind is that HTTPS is not just about encryption/confidentiality but also about authenticity/integrity/non-repudiation. A cert tells you that you are actually connecting to the service that you think you are and it’s not being impersonated by a man in the middle/DNS hijack/ARP poison, etc.

If you’re going to the effort of hosting your own services anyway, might as well go to the effort of securing them too.

source
Sort:hotnewtop