Skip to content

Certificates protection? #1419

Answered by martinrotter
io43 asked this question in Q&A
Discussion options

You must be logged in to vote

Hi.

Yes, in RSS Guard all certificates are trusted by default. While I know that it "may" pose security problem, this feature was not really requested by more people.

And to compromise HTTPS traffic, an attacker would have to hijack/infect your DNS setup somehow and redirect your traffic from your original tintinyrss address to fake one, have fake ttrss running etc. Its not really that easy.

Replies: 1 comment

Comment options

You must be logged in to vote
0 replies
Answer selected by io43
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants