<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Hide rest endpoint that is currently exposed for anonymous Survey123 form in ArcGIS Survey123 Questions</title>
    <link>https://community.esri.com/t5/arcgis-survey123-questions/hide-rest-endpoint-that-is-currently-exposed-for/m-p/1422561#M56772</link>
    <description>&lt;P&gt;I would agree with &lt;a href="https://community.esri.com/t5/user/viewprofilepage/user-id/363906"&gt;@jcarlson&lt;/a&gt;. And to take this one step further, if your Portal exists on the internets, it's being scanned and copied automatically by more people than you can shake a stick at and yell "get off my &lt;STRIKE&gt;lawn&lt;/STRIKE&gt; network". Security is very important, and Esri has numerous recommendations surrounding this (&lt;A href="https://community.esri.com/t5/arcgis-survey123-blog/securing-data-in-public-surveys-survey123-connect/ba-p/898436" target="_self"&gt;here&lt;/A&gt; is a good one targeted at S123 to get started).&lt;/P&gt;&lt;P&gt;Essentially, you can assume people know that your server exists and where it exists. But you can prevent them from getting access to files they shouldn't see via security. Malicious means aside, that security should give you the privacy that you need.&lt;/P&gt;&lt;P&gt;If you want no one to know that your server exists, then you probably need it in an offline environment.&lt;/P&gt;</description>
    <pubDate>Thu, 09 May 2024 14:25:02 GMT</pubDate>
    <dc:creator>abureaux</dc:creator>
    <dc:date>2024-05-09T14:25:02Z</dc:date>
    <item>
      <title>Hide rest endpoint that is currently exposed for anonymous Survey123 form</title>
      <link>https://community.esri.com/t5/arcgis-survey123-questions/hide-rest-endpoint-that-is-currently-exposed-for/m-p/1420827#M56765</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Is it possible to not have the rest endpoint visible that an Anonymous Suvery123 form utilizes?&lt;/P&gt;&lt;P&gt;Is there a way to only allow the Survey123 anonymous website to create the handshake with portal so the rest endpoint isn't visible?&lt;/P&gt;&lt;P&gt;What security measures has anyone else implemented for anonymous Survey123 sites that might be useful?&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Elliott&lt;/P&gt;</description>
      <pubDate>Thu, 09 May 2024 02:22:47 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-survey123-questions/hide-rest-endpoint-that-is-currently-exposed-for/m-p/1420827#M56765</guid>
      <dc:creator>ECarson</dc:creator>
      <dc:date>2024-05-09T02:22:47Z</dc:date>
    </item>
    <item>
      <title>Re: Hide rest endpoint that is currently exposed for anonymous Survey123 form</title>
      <link>https://community.esri.com/t5/arcgis-survey123-questions/hide-rest-endpoint-that-is-currently-exposed-for/m-p/1421741#M56769</link>
      <description>&lt;P&gt;As far as I know, there's not a good way to do this. Public is public, and there's not a way to prevent users from just watching their network traffic to see where their survey responses are going and copy the URL.&lt;/P&gt;&lt;P&gt;What is the security concern with the REST endpoint being visible? You can disable the query capability on the service to prevent anonymous users from &lt;EM&gt;seeing &lt;/EM&gt;the data in the layer, and restrict editing to adding new features only.&lt;/P&gt;&lt;P&gt;You'll still be potentially vulnerable to your form / service getting spammed, but I don't think you can avoid that.&lt;/P&gt;</description>
      <pubDate>Thu, 09 May 2024 12:18:44 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-survey123-questions/hide-rest-endpoint-that-is-currently-exposed-for/m-p/1421741#M56769</guid>
      <dc:creator>jcarlson</dc:creator>
      <dc:date>2024-05-09T12:18:44Z</dc:date>
    </item>
    <item>
      <title>Re: Hide rest endpoint that is currently exposed for anonymous Survey123 form</title>
      <link>https://community.esri.com/t5/arcgis-survey123-questions/hide-rest-endpoint-that-is-currently-exposed-for/m-p/1422561#M56772</link>
      <description>&lt;P&gt;I would agree with &lt;a href="https://community.esri.com/t5/user/viewprofilepage/user-id/363906"&gt;@jcarlson&lt;/a&gt;. And to take this one step further, if your Portal exists on the internets, it's being scanned and copied automatically by more people than you can shake a stick at and yell "get off my &lt;STRIKE&gt;lawn&lt;/STRIKE&gt; network". Security is very important, and Esri has numerous recommendations surrounding this (&lt;A href="https://community.esri.com/t5/arcgis-survey123-blog/securing-data-in-public-surveys-survey123-connect/ba-p/898436" target="_self"&gt;here&lt;/A&gt; is a good one targeted at S123 to get started).&lt;/P&gt;&lt;P&gt;Essentially, you can assume people know that your server exists and where it exists. But you can prevent them from getting access to files they shouldn't see via security. Malicious means aside, that security should give you the privacy that you need.&lt;/P&gt;&lt;P&gt;If you want no one to know that your server exists, then you probably need it in an offline environment.&lt;/P&gt;</description>
      <pubDate>Thu, 09 May 2024 14:25:02 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-survey123-questions/hide-rest-endpoint-that-is-currently-exposed-for/m-p/1422561#M56772</guid>
      <dc:creator>abureaux</dc:creator>
      <dc:date>2024-05-09T14:25:02Z</dc:date>
    </item>
  </channel>
</rss>

