I made some recommendations about quicklisp using http by default and how to lock it down.
I don't know if those are good recommendations anymore. I couldn't manage to follow them myself. I couldn't keep up and my patch approach didnt work.
So, I don't know the best approach with that problem, but I was too confident in my post about security suggestions.