OWASP weekend for @shipnixio seems to be a success!
β Push MFA to production β Send security event email to users when MFA is disabled, enabled and when a backup code has been used to log in β Shorter lived login session to comply with OWASP recommendations
Will try another tagline on the landing as "NixOS web hosting for everyone" seemed to attract negative feedback by hobbyists who are not really the target audience
β MFA with TOTP β Generate backup codes so users can recover if missing authenticator β Brute-force protection on failed MFA attempts with 1hr account lock
Thorough testing on sunday, publish to production monday
β A little touch-up on the public roadmap I made for @shipnixio a while a ago, and start to use it to display what features I am working on β Develop TOTP with Crypto.OTP, but have not implemented it in the web app yet
A little spike in traffic thanks to Hackernews front page
It's nerve-wrecking having lots of strangers reacting both badly and kindly to something I have worked on for so long, but I'm sure this builds character π
β Get mentioned on @HaskelInterlude podcast π β Add logo and adjust color scheme β Give the landing page some love β Write a public security policy because I think it will be important for trust by high value customers
β Get logo from Fiverr logo maker. Not 100% sure yet, but think I like it β Fix bugs in migration flow, solved by deleting more code than I added π β Let users review and modify environment variables before migration