Improve BleachBit.org Security
Hi,
Please upgrade the security a bit more.
Should use Upgrade Insecure Requests @ https://www.w3.org/TR/upgrade-insecure-requests/
Should enable HPKP (HTTP Public Key Pinning) @ https://report-uri.io/home/pkp_hash
Should use CSP (Content Security Policy) @ https://report-uri.io/home/generate
And other security headers @ https://bitcoinsecurityproject.org/WebApplicationSecurityPractices/Secur...
Thanks,
Will
ROCKNROLLKID
Sun, 08/28/2016 - 12:26
Permalink
+1. Though, I thought Andrew
+1. Though, I thought Andrew did update the Content Security Policy when he switched to HTTPS, but perhaps I am mistaken. Anyways, it wouldn't hurt to add these as an extra layer for BleachBit website.
____________________
Also known as Alex.
Moderator for BleachBit and a maintainer for Winapp2.
Check out my open-source group on Steam: http://steamcommunity.com/groups/opencommunity
Windows 10 x64 (switching to ReactOS in the future).
Carl
Fri, 07/07/2017 - 02:55
Permalink
Hi!
Hi!
BleachBit for Windows
Checked for viruses in VirusTotal (https://www.virustotal.com/) crammed troyans!
Eliminate.
The only alternative CCleaner.
I hope to fix it.
andrew
Fri, 07/07/2017 - 20:40
Permalink
Carl: please see the recent
Carl: please see the recent discussion trojans about the false positives
Andrew
---
Andrew, lead developer
Carl
Sat, 07/08/2017 - 07:47
Permalink
Checked (virustotal) Ad-Aware
Checked (virustotal) Ad-Aware - 1 Trojan
Checked Ad-Aware -O Trojan
BleachBit Really safe?
How do you fix a reputation?
Andrew You do not know Russian? (Russian Language)
ROCKNROLLKID
Sat, 07/08/2017 - 12:53
Permalink
Carl. Anti-virus/anti-malware
Carl. Anti-virus/anti-malware have false positives all the time. BleachBit is a popular tool that's been around for years. There has never been any malware in BleachBit before and there never will be. Also, BleachBit is open-source, too, so you can always check the source code for malicious code, if you don't feel safe.
____________________
Also known as Alex.
Moderator for BleachBit and a maintainer for Winapp2.
Check out my open-source group on Steam: http://steamcommunity.com/groups/opencommunity
Windows 10 x64 (switching to ReactOS in the future).
Carl
Sun, 07/09/2017 - 05:25
Permalink
Fear of infection is so great
Fear of infection is so great! Still not trust.
Do so that there are no false positives.
Good luck
fordav
Thu, 03/01/2018 - 00:39
Permalink
Still some layers that can be
Still some layers that can be added, in the order of importance:
Full report and further details on implementation:
https://observatory.mozilla.org/analyze.html?host=www.bleachbit.org
andrew
Thu, 03/01/2018 - 11:16
Permalink
Hi Forday,
Hi Forday,
Yes, it would be good to add more web site security.
I am doing it in steps, while still managing the application and other work. A few days ago I added HTTPS to the last subdomain that did not support it, and now *.bleachbit.org forwards to HTTPS. Also, this week I enabled HSTS with a short max-age to check whether anything breaks. If this goes well, I will increase the max-age. I also looked into CSP, but the configuration for maximum security looks non-trivial.
---
Andrew, lead developer