ZeitOnline/briefkasten

Add to Readme: "No third party elements and links"

Closed this issue · 4 comments

Add to doc or readme:

Because the whistleblower's browser will send the url as referer don't embed (images, scripts, stylesheets and so on) from or don't even link to another (logged or tracked) websites in your templates!

I would go even further and recommend using something like the Tor Browser Bundle(https://www.torproject.org/download/download-easy.html.en), and run an Tor Hidden Service(https://www.torproject.org/docs/hidden-services.html.en) for the whistleblower website! This would protect the whistleblower's location over the internet.

@Mandalka i agree. i have submitted the request to remove all links from the submit form to ZEIT ONLINE. at the very least we should create a clean default template here in this package and move the customizations to another package.

the latter is already in the pipeline but we think it's not a 'showstopper' so we released without it.

update: we have decided to provide 'clean' default markup and factor out the styling of that into a separate package.

keeping this issue open until we have some code to show.

0.1.8 has been released which no longer contains any ZEIT ONLINE specific assets