‹ BackHN Continuity

Thread

Security headers on 4,688 small-business websites: 49.7% met none of 7 criteria

18 points · 15 comments · terrybyte

  1. fitsumbelay · · focus · HN ↗
    for static sites on a VPS it's fair to expect the host to provision these, yes?
    1. rackcrunch · · focus · HN ↗

      [dead]

    2. aetherspawn · · focus · HN ↗
      No, not for a VPS. They are configured at the web server. If you mean CDN, you might be able to use a _headers file or similar to add. Cloudflare can definitely do it.
    3. wink · · focus · HN ↗
      for static sites... it's not that I would call them useless, but most are just not very critical. Clickjacking and any cookie attacks on a site without cookies is pretty useless most of the time.
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.