• 0 Posts
  • 8 Comments
Joined 3 years ago
cake
Cake day: June 9th, 2023

help-circle


  • If the target server is compromised or taken by LEA the data is gone.

    Laying the responsibility into the hands of the user is not ok for such an data aggregating service. Such highly critical, private and intime data should be protected and secure by default.

    Not even transport encryption is enforced in the project. At first glance, http is allowed on local connections?!? Generate a self signed SSL cert on start and pin it in the app. Easy.

    It is no excuse that other services do not follow these state of the art protection measures.