4 ms·
Observatory by Mozilla – automated website security testing tool
- marumari 10y agoI'm the primary developer of the scanner and website, and would be happy to answer anybody's questions, should they have any. :)
- starfox64_ 10y agoI've been running a few tests progressively fixing various issues and now I'm getting an "Error: Site down" error however I am still able to access my website over HTTP and HTTPS on my browser.
- mc42 10y agoI find it interesting how the first website ever, being info.cern.ch, fails 6 of the 10 tests, getting a 0/100.
- marumari 10y agoIt also has an invalid website certificate. Kind of a shame that it's so neglected, but it's a pretty good example of what happens to sites when they're allowed to sit for too long.
- mc42 10y agoI was under the impression it was recently updated for the 25th anniversary. However, I can understand not adding "security" in the name of preservation. Real shame.
- marumari 10y agoThe nice thing is that most of the security measures -- aside from Subresource Integrity -- can be done without changing any of the actual content.
- bigtones 10y agoMicrosoft and Google both score a "D", Mozilla itself scores a "D-", Apple and Amazon both score an "F"
- marumari 10y agoOn the plus side, there are sites doing really well, like GitHub (A+), HackerOne (A+), and Twitter (A). Even Facebook is doing pretty well, with a B. Hopefully sites like the Observatory help sites do better. We're working really hard on getting mozilla.org to the point where it also gets an A+.
- galaktor 10y agoI find it interesting (and a bit disappointing) that while github.com gets an A, a static page I host on github pages received an F. Would be great if Github would help pages hosted there be more secure by default.
- technion 10y agoWhich of the security tests performed by this tool do you feel have a significant impact on a static page? Some of these things, such as subresource integrity, will be down to you and what you do with the code. Many of these tests have very little baring on how 'secure' a static page is.
- manigandham 10y agoA lot of these headers are repetitive, need to standardize instead of just making more convoluted options.