Add conmtent for "How to find a good server"

rugk 2016-08-24 23:21:51 +02:00
parent c6c4cd9cc5
commit 6f846610ef

12
FAQ.md

@ -17,7 +17,17 @@ The only way to prevent this is to set a long, secure password when uploading. Y
### Which PrivateBin server should I use?
[TODO]
Generally it is recommend to host your own instance of PrivateBin. You can do this with cheap equipment directly at home if you do not fear setting up a server.
If you cannot do this, you need to find a server, who you trust. On the one hand this means you have to trust the server operator. For this a relative or friend may help you or even set up an instance. You may also trust certain organisations or the developers of PrivateBin, who host their [own public instance](https://privatebin.net/).
So on the other hand you should check the technical measures the server administrator used, so you can trust the server. Here is a small checklist with recommendations:
* Check that the server uses HTTPS. On https://privatebin.net/ you can e.g. see that it does, because the address starts with `https://`.
* Enter the web address into https://www.ssllabs.com/ and let it check the server. It actually checks the HTTPS configuration.
We recommend that servers have at least an **A rating**. If they have less, you might look for a better server. If they have A+ you are on a good site!
* Enter the web address into https://securityheaders.io/. Here we also recommend an **A rating** or better.
If a requirement is not fulfilled, you may contact the server administrator and ask them to improve it. Of course you can also suggest them improvements if they do not have the best ratings available, because they are reachable by any webserver admin, but they may decline to change their configuration in this way.
### The URL is so long. Can't I just use a URL shortener?