Using HFS + STunnel to access private files through HTTPS

HFS - HTTP File Server

I occasionally use this program to transfer files that are too large for email, but then I always disable/close it afterwards. The thought of leaving it on 24/7 has crossed my mind, but I'm not sure how secure this would be (I already have it setup to require a username and password).

Does anyone happen to know how secure this program is, or what the server software is based on? Since it's an older program, I'm worried it may have some well known vulnerabilities. (Also, I'm not sure if HTTPS in general is somehow less secure than setting up a VPN?)

I know there are plenty of other solutions out there, but I really like the idea of accessing my files through HTTPS (so I don't have to install anything to anyone's computer). I want to be sure there isn't an easy/obvious vulnerability, in case some stranger does happen to stumble upon it (no domain name, it's just an ip address with custom port number).

submitted by /u/username_is_elephant
[link] [comments]

from hacking: security in practice https://ift.tt/ZkdM0uS

Comments