3 ms·
didn't know of HSTS, thanks. where would one keep up with stuff like that other than keeping up with new rfc's?
by bobcattr 14y ago
didn't know of HSTS, thanks.
where would one keep up with stuff like that other than keeping up with new rfc's?
- moonboots 14y agoagl's blog is a good source: http://www.imperialviolet.org/ http://www.imperialviolet.org/
- alistair77 14y agoOWASP has lots of useful security info, https://www.owasp.org https://www.owasp.org
- ivanr 14y agoI maintain a complete guide to SSL/TLS deployment: SSL/TLS Deployment Best Practices https://www.ssllabs.com/projects/best-practices/ https://www.ssllabs.com/projects/best-practices/
- hnolable 14y agoYou may want to integrate some of the advice from here in your HSTS section: http://coderrr.wordpress.com/2010/12/27/canonical-redirect-pitfalls-with-http-strict-transport-security-and-some-solutions/ http://coderrr.wordpress.com/2010/12/27/canonical-redirect-p... It seems even github is susceptible to this. That is, for people who type www.github.com into their browser rather than github.com. They both did the redirect wrong, as well as left off HSTS of https://www.github.com https://www.github.com.