Move third-party resources to own servers
Closed this issue · 3 comments
KOLANICH commented
Using a third-party resource is a privacy and security risk.
ljharb commented
a) it's not; b) can you be specific about which resources?
KOLANICH commented
a) it is
b)
https://netdna.bootstrapcdn.com/font-awesome/3.2.1/font/fontawesome-webfont.ttf?v=3.2.1
https://netdna.bootstrapcdn.com/font-awesome/3.2.1/font/fontawesome-webfont.woff?v=3.2.1
https://fonts.googleapis.com/css?family=Raleway:700
https://cdn.jsdelivr.net/autocomplete.js/0/autocomplete.min.js
https://cdn.jsdelivr.net/algoliasearch/3/algoliasearch.min.js
https://netdna.bootstrapcdn.com/bootstrap/3.0.3/js/bootstrap.min.js
https://code.jquery.com/jquery-1.10.1.min.js
https://grtp.co/v2.js
https://www.google-analytics.com/analytics.js
https://netdna.bootstrapcdn.com/font-awesome/3.2.1/css/font-awesome.min.css
ljharb commented
All those seem fine. The inconvenience doesn't outweigh the insignificant risk of these HTTPS resources going rogue, on this email mailing list website.