Application security & protocols
In Play Digital Signage, we take security of your data very seriously. This page gives a brief summary of the security procedures at Play Digital Signage
How is my web account secured?
Your passwords are stored in our database encrypted using top of the line Argon2 password hashing algorithm. This way, your passwords are not known to our staff and will not be compromised in the unlikely event of a data breach. Your login sessions are facilitated using Secure HTTPS-only cookies to eliminate the risk of eavesdropper stealing them by intercepting your connections.
When you register (or change password), we will go the extra mile to check your password against a public database of leaked passwords to ensure that you’re not using an insecure password. Your password does not leave our servers during the check, we use K-anonymity protocol to check the password at a trusted service HaveIBeenPwned.
- All the communications between your device and browser are protected using SSL and DNSSEC.
- We backup your data multiple times a day.
- We use CloudFlare to detect and mitigate hacker attacks.
- We support Two-Factor Authentication.
- All the communication between our servers is encrypted and done over private networks.
How secure are communications?
All connections to our servers are HTTPS, that means that the traffic is encrypted, that includes web-socket connections. We have disabled SSLv3 and use TLS exclusively.
The Internet traffic is routed through Cloudflare network, which protects our servers against Denial Of Service (DoS) and brute force attacks.
How are my files secured?
Your files are hosted on Digital Ocean Spaces service, either in Paris or San Fransisco data-center depending on your location. While we can not make the files private, because the players need to be able to download the files from the Internet, we generate a unique id for each file, so the URL is virtually impossible to guess. For an example this is the URL of an uploaded file:
An attacker has better chances of guessing your password! (so make sure it’s secure)
If your files can not be stored on the public web due to company policy or any other reason, it’s also possible to reference files from a private file server, read more on private files.
How are players secured?
When a player is linked to a user account, the server generates a unique secret token that is sent to the player once. Every subsequent request made by the player to our servers requires the token to be present in order to prevent malicious attacker from impersonating as the player itself. The weakest link is the physical player security, so make sure it’s out of sight and if possible, then out of reach!
Where is my credit card information stored?
We use Stripe as our payment gateway and they take care of storing your information securely. Stripe is PCI Data Security Standard certified company. When you link a credit card with your account, your credit card numbers are sent to Stripe servers directly from your browser, our system does not store or process your credit card information.
Which external services the players connect to?
In case the player is behind a corporate firewall, you need to white-list following domains (port 443):
- We recommend whitelisting all subdomains of *.playsignage.com to be future-proof. If wildcard white-listing is not possible, then the player may also use following sub-domains:
- stream.playsignage.com OR us-stream.playsignage.com (WebSocket connection)
- release.playsignage.com (only for Windows / OSX / Linux players to auto-update)
- eu-storage.playsignage.com OR us-storage.playsignage.com (File storage)
- quotes.playsignage.com (Quote plugin is using this endpoint to fetch quotes)
- onthisday.playsignage.com (Today In History plugin is using this endpoint to fetch data)
- proxy.playsignage.com (Weather, Facebook and Instagram plugin use this domain)
- my.playsignage.com (Location of proxy used to fetch insecure non-HTTPS web resources)
- logging.playsignage.com (Optional, for us to receive player logs and help us debug issues)
- analytics.playsignage.com (Optional, if you want to use analytics functionality)
- Some plugins communicate with external systems:
- images.unsplash.com (When using images from Unsplash integration plugin)
- player.vimeo.com (When using videos from Pixabay integration plugin)
- media1.giphy.com, media2.giphy.com, media3.giphy.com, media4.giphy.com (When using GIFs from Giphy integration plugin)