Home / Companies / GitHub / Blog / Post Details
Content Deep Dive

Sidejack Prevention Phase 3: SSL Proxied Assets

Blog post from GitHub

Post Details
Company
Date Published
Author
Corey Donohoe
Word Count
238
Company Posts That Month
13
Language
English
Hacker News Points
-
Post removed?
No
Summary

GitHub has addressed the issue of session hijacking and mixed-content warnings on its website by implementing a solution that ensures secure embedding of images via GitHub flavored markdown. Previously, some pages allowed embedding images that resulted in mixed-content warnings, distracting users and compromising their sense of security. The solution involves rewriting the src attribute of img tags to proxy through GitHub's secure asset servers, thus eliminating the warnings. This technical change was executed by developing a simple HTTP proxy in Node.js, integrated with GitHub’s existing nginx setup. Users are encouraged to report any remaining issues through support tickets, as the new system appears to be functioning well. The company is now focusing on further feature development after resolving this security concern.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.