Today is bank holiday in my country so I have spare time.
I'm sorry to see that Kym depends on this financial system.
I'm not against ads.
I'm against:
-Tracking
-Malwares
-and "big-datamining"=https://media.ccc.de/v/33c3-8414-corporate_surveillance_digital_tracking_big_data_privacy.
(and "javascript"=https://www.gnu.org/philosophy/javascript-trap.en.html ) but that's secondary.
The actual ads on kym are trackers, malwares and datamining programs.
Plus it's clearly stated in the "privacy policy"=corp.cheezburger.com/legal/privacy-policy/ that any kind of data is being sold, not just ads.
The website crawls with external spyware/tracking and malware
Wen you go on a website you're normally on 1 domain but with Kym there's more than 30 websites that connect to your PC or knows that you go on Kym when you connect to it.
-amazon-adsystem.com
-civicscience.com
-air.tv
-ntv.io
-complex.com
-static.chartbeat.com
-google-analytics
-graph.facebook.com
-pinterest.com
-indexww.com
-crwdcntrl.net
-doubleclick.net
-casalemedia.com
-advertising.com
-connatix.com
-quantcount.com
-criteo.com
-openx.net
etc…
Just look with "lightbeam"=https://www.mozilla.org/en-US/lightbeam/
The problem with Kym are numerous:
-No, very ease automated "Lets encrypt" cert for encrypted connections with your users ?
Man in the middle aren't important and dangerous, it's well known that people "never put the same password"=https://github.com/danielmiessler/SecLists/tree/master/Passwords or use a totally random passwords like "L6_)H2µ=" (sarcasm)
-Constant Tor ban.
It's not like to post you need to subscribe (sarsasm).
-Trackers in email links ?
Privacy is useless :p (sarcasm)
I'll whitelist websites who use ads the day that advertisers will:
-Not exploit javascript security holes (or other security holes) to insert malware.
-Not track the user where he goes.
-Not datamine every brink of information possible.
Aka be like a simple paper IRL advertisement and not a javascript monstrosity.
If the admin reads this and at least make some Lets enrypt cert, please don't save the passwords of your userbase in cleartext.
In fact don't store passwords, Hash them and store the hashes.
In fact don't make simple hashes use cryptographic hashes (SHA256, SHA512, RipeMD, and WHIRLPOOL).
"In fact"=https://en.wikipedia.org/wiki/Rainbow_table don't simply just cryptographic make hashes, "salt"=https://en.wikipedia.org/wiki/Salt_(cryptography) them
Finally, install Gentoo
Take care an I hope that you'll find a way to finance the website and to not sell the privacy, security of your users to finance the website.