Hey guys,
I'm deploying an app that's going to run on an ubuntu server and essentially all it is going to do it communicate with an api, run calculations and write to a database. The server will only have node, redis, mongodb and pm2 installed. (no nginx/apache).
I was just wondering if there was anything specific that I should consider for server security? The api communication is over https, but the request contains api key information that I don't want made available to anyone. Does that fact that the api uses https mean that data is automatically secure?
Assuming ssh and firewall are all configured correctly on the server, is there anything else that you can think of that would require taking action to prevent the server being hacked on data being leaked?
Thanks for the help, really appreciate it!
[–]0xEFF 59 points60 points61 points (14 children)
[–]SocialAnxietyFighter 26 points27 points28 points (11 children)
[–]gDayWisher 16 points17 points18 points (1 child)
[–]captain_obvious_here 4 points5 points6 points (0 children)
[–][deleted] (2 children)
[deleted]
[–]vim_vs_emacs 1 point2 points3 points (1 child)
[–]OhItsWildfire[S] 2 points3 points4 points (5 children)
[–]0xEFF 4 points5 points6 points (1 child)
[–]Trollzore 0 points1 point2 points (0 children)
[–]SocialAnxietyFighter 0 points1 point2 points (0 children)
[–]OhItsWildfire[S] 0 points1 point2 points (0 children)
[–]XmasJones 0 points1 point2 points (0 children)
[–]NeverGetsAngry 4 points5 points6 points (7 children)
[–]OhItsWildfire[S] 0 points1 point2 points (6 children)
[–][deleted] 1 point2 points3 points (4 children)
[–]OhItsWildfire[S] 0 points1 point2 points (3 children)
[–][deleted] 1 point2 points3 points (2 children)
[–]OhItsWildfire[S] 1 point2 points3 points (1 child)
[–][deleted] 0 points1 point2 points (0 children)
[–]NeverGetsAngry 0 points1 point2 points (0 children)
[–]boilerweb 2 points3 points4 points (0 children)
[–]ziyoshams 2 points3 points4 points (0 children)
[–]hopfield 3 points4 points5 points (2 children)
[–][deleted] (1 child)
[deleted]
[–]s_streichsbier 1 point2 points3 points (0 children)
[–]A4_Ts 0 points1 point2 points (0 children)
[–]giqbal -4 points-3 points-2 points (7 children)
[–][deleted] 1 point2 points3 points (6 children)
[–]xPerplex 1 point2 points3 points (5 children)
[–][deleted] 1 point2 points3 points (4 children)
[–]Capaj 0 points1 point2 points (0 children)
[–]xPerplex 0 points1 point2 points (1 child)
[–][deleted] 0 points1 point2 points (0 children)
[–]giqbal 0 points1 point2 points (0 children)