I just got aware of the fact that bitcoin.org is served through pages.github.com.
ping www.bitcoin.org
PING bitcoin.org (207.97.227.245) 56(84) bytes of data.
64 bytes from pages.github.com (207.97.227.245)
I haven't develved deep into the issues surrounding github.com, neither have I used it much,
but there's been some writings about compromises of github during the last months, so I was
wondering if we would not be safer off disconnecting the bitcoin.org page with it's downloadable
binaries completely from github.com.
Could a github compromise lead to binaries on bitcoin.org being compromised ? With the current
setup, it seems so.
In my personal opinion, bitcoin.org along with it's binaries should be hosted on a hardened server,
separate from any other service.
Please discuss.