5 ms·
Is your website Secure!
- deleted 2y ago[deleted]
- rpgbr 2y agoBroken without JavaScript.
- bubblesnort 2y agoBroken with JavaScript enabled too
- yellowapple 2y agoEven with JavaScript the main page seems broken; the text box doesn't actually do anything. Works better (for me at least) by using the actual URL (e.g. https://inspect.new/news.ycombinator.com https://inspect.new/news.ycombinator.com) instead. EDIT: seems like the form submission is doing a POST to https://inspect.new https://inspect.new, which returns a 500 error.
- Timwi 2y agoThe direct URL still doesn't work for me, it just redirects straight back to the main page.
- Aachen 2y agoBetter title: HTTP header checklist
- dbg31415 2y agoSo many good lists out there to just copy off of... https://blog.postman.com/what-are-http-headers/ https://blog.postman.com/what-are-http-headers/ https://cheatsheetseries.owasp.org/cheatsheets/HTTP_Headers_Cheat_Sheet.html https://cheatsheetseries.owasp.org/cheatsheets/HTTP_Headers_... https://www.geeksforgeeks.org/http-headers/ https://www.geeksforgeeks.org/http-headers/
- upon_drumhead 2y agoThey only give themselves 85/100. https://inspect.new/inspect.new https://inspect.new/inspect.new
- amiga386 2y agoThey give almost the entire planet 85/100, because they've decided that every webpage must have a Permissions-Policy header. This is disingenuous. Permissions-Policy is an extension of Content-Security-Policy. If you embed third party contents in your page, you will absolutely want a CSP and a permissions-policy. If you made the site yourself, if what's being served up is all yours and no third party code, you have no need for this header. Because you know you won't ask for permissions you don't need. This service has no idea whether you're a 3rd-party-embedding site or not, and can't know because the 3rd-party data could appear directly in the HTML (e.g. blog comments). So they can't say you must have this header. It's a false positive to say you need it, and it's needless box-ticking to add one if you don't need one. Ironically, my own site would pass this because for a fleeting time in the past, Google were trying to force new ad-tech on everyone, and the only way they offered to opt out (it was not opt-in as it should be) was for site owners to write Permissions-Policy:interest-cohort=() -- see https://amifloced.org/ https://amifloced.org/
- tommy_axle 2y agoYes, but you would also need to guarantee that content that does 3rd party stuff can't get injected.
- progbits 2y agogoogle.com scores 50/100. This is one of those scanners crappy pentesters use for multi page reports of false positives?
- mavamaarten 2y agoHah this triggers me. Last week we got a pentest done on our apps. This week we got some high-prio tickets on our board because they found major security violations!!! Our app, which uses an API, used a dangerous permission! "android.permission.INTERNET" How they can report this with a straight face, I don't know. Makes me want to go in the security business though, if that is the level of competence I'm absolutely positive that I could do that job and earn a lot more than a generic app developer.
- CrimsonRain 2y ago> Why isn't the app obfuscated, why can it be run on rooted device and why doesn't the app use https with pinning? The app in question: a wrapper of a PWA ticket purchase webapp which saves no payment info. Being able to run on rooted device was determined as severe category.
- SebFender 2y agoFrom experience, most are very junior and use automated solutions which just don't make sense. When we do ours we really focus on core elements and very material findings... as everyone should. But competency is so rare in this field it's hard to follow.
- archerx 2y agoI made something similar a long time ago, it's mostly aimed at people that use CMSs like Wordpress or Joomla. The database was created using the most common attack endpoints bots have tried on my own sites. https://prober.dev https://prober.dev if anyone wants to try it out
- samjanis 2y agoThat test is actually funny, in a good way; like how you said you got those links in the first place on the about page is pretty much what any experienced web dev finds out day-to-day. Most sites I sent to it came back with plenty of false positives, mainly because htaccess rewrites resolve the URIs as query string IDs and returned empty pages with "Sorry, but the information you're looking for doesn't exist..."
- archerx 2y agoThanks for trying it out. It’s been a while but I’m sure the test checks for a 404 so if those pages gave a 404 they won’t be recognized as a false positive. I tried leaving some text about possible false positives because some people told me it can make others panic if they don’t really understand web dev well.
- endre 2y agoBroken with Brave default shields.
- dbg31415 2y agoWhat's better about this vs. Mozilla Observatory. https://developer.mozilla.org/en-US/observatory https://developer.mozilla.org/en-US/observatory (formerly https://observatory.mozilla.org/ https://observatory.mozilla.org/) Or Security Headers? https://securityheaders.com/ https://securityheaders.com/ Or VENOM? https://github.com/oshp/oshp-validator https://github.com/oshp/oshp-validator Applaud the effort, these are things that more devs should be aware of when building websites... Hey some specific feedback on this tool... On mobile, it has a lot of "view port wobble" and the input fields aren't keyed right, it's just using a straight text input field so you don't get any ".com" buttons as you type. The forms use light gray text on a dark gray background -- that isn't at all aligned with WCAG standards. https://i.imgur.com/BNCC5Dx.png https://i.imgur.com/BNCC5Dx.png And it really needs to work on what it thinks is a valid URL. https://i.imgur.com/N1ctafd.png https://i.imgur.com/N1ctafd.png Small UX stuff like that annoy me more than if a page has a privacy policy setup correctly. (= Lastly, Permissions Policy... good concept, but still in "DRAFT" so not quite something you can ding users for not adopting just yet. https://www.w3.org/TR/permissions-policy/ https://www.w3.org/TR/permissions-policy/ https://caniuse.com/permissions-policy https://caniuse.com/permissions-policy If you want to play around with it, here's a good tool to generate examples. https://www.permissionspolicy.com/ https://www.permissionspolicy.com/ Oh lastly lastly, there are some really easy tools out there for helping to create a Content Security Policy, these really speed up the process. (Just make sure you disable your ad-blockers before running.) https://csper.io/generator https://csper.io/generator https://github.com/april/laboratory https://github.com/april/laboratory
- mahmoudgalal 2y agoThis is a very handy feedback, I really appreciate it. thanks for the suggestions and will be more features comes out to be better to enhance the experience and the knowledge for devs about some other security manners
- phantomathkg 2y agoJust keep getting "Connection error, please refresh the page."
- lexokoh 2y agoI think they are getting an overload. I tried for some of my sites and it worked.
- deleted 2y ago[deleted]
- pjmlp 2y agoQuite lousy experience on the input field, keeps complaining to enter a valid url. Additionally it seems to have issues with random sites given as parameter, only working with the displayed examples.
- jesprenj 2y agoIt does not seem to support IDN domains.
- lexokoh 2y agoThe experience is fine for me, though yes, I think it doesn't support some domains yet.
- red_trumpet 2y agoFor starters, they don't support any subdomains...
- lexokoh 2y agoYes, i saw that. I think it might be intentional
- mahmoudgalal 2y agonow it support it. we used to avoid that, and making the input field very sanitised about the input
- mahmoudgalal 2y agonow it support it. we used to avoid that, and making the input field very sanitised about the input
- freitasm 2y agoYes, I can't get it to inspect some of my domains.
- johnisgood 2y agoThat contact form being open automatically and not being able to hide it is annoying, I have to use uBlock to hide it. Additionally, I get "Connection error, please refresh the page." for a website that clearly is accessible.
- lexokoh 2y agoI experienced this and tried again. It worked fine. Servers i think.
- freitasm 2y agoAnd 502 Bad Gateway, even though behind Cloudflare.
- lexokoh 2y agoIt works fine, so far. I think their server was down then
- Puts 2y agoThis scan is so limited that I wonder if it even could be directly damaging. If the average Joe who set up a CMS for his business runs this and thinks "Great I got a 90% score our site is secure".
- lexokoh 2y agoI think it's more of a start. I don't think an average Joe who got 90% will assume this. 90% is big.
- arghwhat 2y agoAverage Joe and businesses alike will assume that a tool telling them their site is secure means that they don't have to worry much about it. A tool that can easily be made to report "100% secure" is then quite harmful. Even large corporations rely largely on buying reports, and in turn buying products to fix the results of those reports as their primary security strategy.
- lexokoh 2y agoI get your point, but I still can't believe the average Joe would think like this. Also, large corps get SOC2, yet they are still not secure. Also, auditors use tools like this or have their tools to get reports telling them they are 100% secure. No one should ever assume 100% security, even when the odds suggest otherwise. Maybe you are right.
- arghwhat 2y ago> Also, large corps get SOC2, yet they are still not secure. SOC2/ISO27001 audits are just "are you living up to the processes you defined yourself for SOC2 compliance", not "are you secure". It is dealt with by whatever Compliance unit the company has and only serves to avoid legal issues, and has nothing to do with whoever runs IT security. Security audits is usually quite laughable, and work tends to be initiated by security vendors who happen to have a scan that gives some "very bad" result which they just so happen to have a silver bullet product to fix. Then the company uses that scan until the next company comes along... Few companies take security seriously, designing things for security rather than just buying whatever bandaids they see in the store.
- jonplackett 2y agoOnly gets 85/100 itself https://inspect.new/inspect.new https://inspect.new/inspect.new
- tambourine_man 2y agoWhy use an exclamation mark and capitalize secure?
- k__ 2y agoDoesn't seem to work. Either it complains that my domain isn't valid in the input, or it redirects to the landing page if I add my domain to the URL.
- lexokoh 2y agoI think some domain types are not supported yet. I have experienced this as well, but my other domains work.
- mahmoudgalal 2y agonow it support it. we used to avoid that, and making the input field very sanitised about the input
- neallindsay 2y ago"comprehensive security report card" is overselling it a bit, but it's a decent checklist of some things that are useful to consider for security.
- SebFender 2y agoAutomated web assessments are very low value - from them to companies like Qualys and automated scanners save your time and money.
- lexokoh 2y agoDo you have an example of automated scanners?
- m0wer 2y agonot working...
- samjanis 2y agoThey gave schneier.com 55/100. https://inspect.new/schneier.com https://inspect.new/schneier.com
- lr0 2y agoGoogle.com gets a 50/100 rate from this website.