‹ BackHN Continuity

Thread

Security headers on 4,688 small-business websites: 49.7% met none of 7 criteria

18 points · 15 comments · terrybyte

  1. aetherspawn · · focus · HN ↗
    It’s ridiculous that the answer to a secure web is for everyone to sprinkle the magic salt and not something on the browser side
    1. alserio · · focus · HN ↗
      we'd need an epoch like reset to good defaults
      1. aetherspawn · · focus · HN ↗
        For important issues like security - just break the web, it will adjust.
        1. sublinear · · focus · HN ↗
          PoC? HN would be a great place to show one.
    2. rackcrunch · · focus · HN ↗
      Referrer-Policy shows it can work. When the header is missing, browsers fall back to strict-origin-when-cross-origin. 86.6% of the sites we scanned don't send it, and we didn't count that as a failure for that reason. The other headers don't have a safe default like that yet.
      1. axospaxos · · focus · HN ↗
        That sounds more like it is a condemnation of all these other headers that can't work for 86.6% of sites by requiring nothing.
        1. rackcrunch · · focus · HN ↗

          [dead]

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.