Suggestion: HTTPS download link
Posted: 20 Nov 2014, 18:30
We love CSF, but we're concerned that no secure download is available.
Since CSF is critical to many servers' security, it could be the target of attack. Imagine a man-in-the-middle or poisoned DNS providing a modified csf.tgz. It could contain a backdoor or other nasty code that you're installing without knowing any better.
Please consider providing the download link and updates over HTTPS/SSL with a trusted cert. It would ensure that the install is coming from you.
Since CSF is critical to many servers' security, it could be the target of attack. Imagine a man-in-the-middle or poisoned DNS providing a modified csf.tgz. It could contain a backdoor or other nasty code that you're installing without knowing any better.
Please consider providing the download link and updates over HTTPS/SSL with a trusted cert. It would ensure that the install is coming from you.