Uploaded image for project: 'Planet4'
  1. Planet4
  2. PLANET-1786

Implement security suggestions as previously identified

XMLWordPrintable

    • Icon: Task Task
    • Resolution: Done
    • Icon: Should have Should have
    • None
    • 8
    • Security
    • Sprint #29, Sprint #30, Sprint #31, Sprint #32


      • Here're a few infra security objectives for P4 I think we need to prioritise:

       
      1. Application level firewall, eg Wordfence, to handle brute force password attempts, xmlrpc, background-radiation hack attempts on known bad urls
       
      2. Rate limiting at service / load balancer / CDN level, to mitigate against /wp-login.php and /wp-admin/ spam before it gets to the application layer
       
      3. Deny all traffic to the application that doesn't come from Akamai
      4. Go forward with Google's Project Shield DDoS / CDN protection

       

      Task assigned to Ray as the driver, if not implementer

            rawalker Ray Walker (Inactive)
            svickers Simon Vickers (Inactive)
            Votes:
            0 Vote for this issue
            Watchers:
            0 Start watching this issue

              Created:
              Updated:
              Resolved: