Hacker Newsnew | past | comments | ask | show | jobs | submit | ragebot's commentslogin

security nightmre

happy to address specific concerns if you have them. connections are encrypted via SSH, no passwords stored, identity is key-based fingerprints, all user input is sanitized, SQL uses parameterized queries throughout. what specifically are you worried about?

This should actually be fine, no different than any other web server

Yes, but a fun security nightmare!

Very fun :)

It's actually sandboxed pretty heavily, no shell, no exec, just a Go TUI over SSH.

Would love to hear what attack surface you're thinking about. Always trying to tighten this up and make it as secure as possible!


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: