Skip to content

Commit

Permalink
point out MITM risk when not using https for querying the IP
Browse files Browse the repository at this point in the history
  • Loading branch information
ThomasWaldmann committed Nov 15, 2014
1 parent 36d4445 commit 70ab452
Showing 1 changed file with 5 additions and 0 deletions.
5 changes: 5 additions & 0 deletions docs/security.rst
Expand Up @@ -25,6 +25,11 @@ not work).

On the hosts overview page, we show whether we received the last update via TLS.

Please note that if you like security, you also need to use https (with
certificate verification) if you use the web-based method to query your IP
address. If you use http, a powerful attacker could MITM your request and
tell you a wrong IP, which your updater then would happily write into DNS.


Login with remote vs. local Account
===================================
Expand Down

0 comments on commit 70ab452

Please sign in to comment.