Following the last version of the OpenAPIs, is a bit crazy, but I may need to setup this, within the server database application, and in Cloudflare Schema Validation mechanism, to ensure that only authorized connections can talk with my servers. This is going to be a crazy experience, but I will setup all the recommendations in a paranoid style. The Application I am about to release before the end of the year, will follow a bit the description of wiki texts, but most of the original approachs described, will not be the same. As the first release, I wish to create the best conditions to be sure that this application will run for all users in a secure way. Privacy of users are managed by users and I only control Groups Registrations, in case a group wish to participate in this World Wide Challenge for Image Purpose Only, so the group can promote themself's, based on the actions they do, while each user, can learn about how others see them in different social contexts.
In my opinion, this features can be useful to all users that wish to improve their professional skills, while can help them in many other aspects of society. This first release will not have a blockchain associated and is designed to be so simple, that any child can understand.
Anyway, using SSL connections for encryption, for authentication and authorization, is the minimum requirements I will set, for this first version. I will probably change the default ports for the database, like all other services that I need to run, that will not run using the default configurations.
At irc.libera.chat I had the opportunity to talk in some really cool channels about some of this topics, like #security, #OpenBSD and specific database channel that I will use, and since attackers always follow the default configurations on their scripts, changing the default configurations, is a good trick to make them lose time. A regular backup system is as well recommended, and hardening the system is another awesome approach to make their fun game, harder. I can even block entire countries and block IPs who try their luck, but since the application will be release in all countries in the world, blocking entire countries is not what I should do. Gladly for you I am not fan of torturing and killing people, but that could be a delicious approach to create fear on attackers. Since I don't agree with those approach's, the attacker have a bit more freedom to attack, but other mechanisms will be created to deal with that "eternal" problem.