However, be careful with the terms of non-commercial usage (Enforced heavy metrics)
"You agree that the product will send usage data to validate your compliance with the license terms and anonymous feature usage statistics..."
"The information collected under Sections 4.1. and 4.2. may include but is not limited to frameworks, file templates used in the Product, actions invoked, and other interactions with the Product’s features."
However, be careful with the terms of non-commercial usage (Enforced heavy metrics)
"You agree that the product will send usage data to validate your compliance with the license terms and anonymous feature usage statistics..."
"The information collected under Sections 4.1. and 4.2. may include but is not limited to frameworks, file templates used in the Product, actions invoked, and other interactions with the Product’s features."
"What happens though if namecheap goes out of business during that?"
.COM agreement between registrars and ICANN requires registrars to regularily store all registrant contact infos in IronMountain and set ICANN as escrow, therefore allowing ICANN to contact all registrants should a registrar fold and allow them to transfer to another registrar. Another reason to keep the domain ownership informations up-to-date. [1]
I do, it works great with their docker-compose install - processing a few billion events per day here. Installation and subsequent minor/major upgrades without any flaw so far, plus they have extensive documentation for the self hosted version which is to note.
Forensics reports would be nice indeed, but even Google doesn't send them to the RUF address. Never got one report in 4 years of DMARC. Only RUA. Maybe one day..
I’m the author of the issue on Gitlab (small world, isn’t it ?)
Yes the message is confusing and I agree that .mov isn’t a MIME type but I was merely reporting the error message shown ( plus, they added .mov in their list of file types and had aliased it to .mp4 format, please see: https://gitlab.com/gitlab-org/gitlab/-/blob/master/config/in... )
If it can help you, you should know that they test everything over a VPN that doesn’t support UDP. So if your app makes use of UDP you’ll need a fallback method.
And they use dropbear to connect to the router to do changes from remote/customer service/online customer portal, if you're curious (you can see it in logs of the router, Inteno ones)
I tried it around November 2019, really liked Notion and the UI/UX of the product for some note taking/personal knowledge base, however I had to contact their security team through their support because TLS 1.0 was still enabled at this time.
My second concern is that their .so domain is the TLD of Somalia (with all the risks it brings in case of malicious takeover), and .so zone doesn't even support DNSSEC, once again this is a big issue for me, especially for an app that hosts "personal data" (I see they also make calls on a .com domain, but the .so main domain issue still stands). Support told me they would change the domain in the future but still didn't happened.
It's only my personal security stance/paranoia, but my 2 cents of what happened with them.