Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

How battle-ready (that is, security-wise) is this beautiful piece of software?


In what regards? Caddy has never been vulnerable to a number of widespread CVEs including Heartbleed, DROWN, POODLE, and BEAST. Caddy uses TLS_FALLBACK_SCSV to prevent protocol downgrade attacks. Like any other web-facing service, it's exposed to DDoS attacks. I've never heard of a machine being compromised by exploiting Caddy...

If anyone has a vulnerability to report, please email me directly[1] (or if it's not serious, a PR would be faster).

[1]: https://github.com/mholt/caddy/blob/master/CONTRIBUTING.md#v...




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: