Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
Scott_Helme_
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
8 ms
·
61.
▲
by
Scott_Helme_
10y ago
How about 'what a bunch of jerks to connect it to the internet and not secure it properly'?
62.
▲
by
Scott_Helme_
11y ago
Yeah, the 2 main issues with the VIN are as you say, the targeted vehicle in your presence, or enumerating all vehicles as they're sequential. Not great either way.
63.
▲
by
Scott_Helme_
11y ago
Rather unfortunate wording!
64.
▲
The SecurityHeaders.io Chrome Extension
(scotthelme.co.uk)
1 points
by
Scott_Helme_
11y ago
|
0 comments
65.
▲
Security headers in the Alexa Top 1M
(scotthelme.co.uk)
2 points
by
Scott_Helme_
11y ago
|
0 comments
66.
▲
Let's Encrypt Smart Renew
(scotthelme.co.uk)
3 points
by
Scott_Helme_
11y ago
|
0 comments
67.
▲
by
Scott_Helme_
11y ago
HPKP is HTTP Public Key Pinning, you aren't pinning certificates, you're pinning the public key. This means that you don't necessarily need to change any pins when you renew certificates as the certificate can use the same ke
68.
▲
by
Scott_Helme_
11y ago
You can also pin the public keys of certificate authorities to limit which ones can issue for your domain and not have to worry about key backups. GitHub do this as you can see here: https://report-uri.io/home/pkp_analy
69.
▲
by
Scott_Helme_
11y ago
Did that fix it? Failing that, do you have any extensions or other things that might affect this?
70.
▲
by
Scott_Helme_
11y ago
Interesting, what version of Firefox is this? You can see in the CSP that 'self' is a defined keyword for both the script-src and style-src directives: https://report-uri.io/home/analyse/https%3A%2F%2Fsec
71.
▲
by
Scott_Helme_
11y ago
Exactly right. The only browser that will send HPKP reports right now is Chrome and that was very recent.
72.
▲
by
Scott_Helme_
11y ago
No, but that doesn't impact the operation of enforcing the use of their public keys which is the main purpose. It's definitely preferable to have reporting though.
73.
▲
by
Scott_Helme_
11y ago
There's also https://starttls.info/ which will check mail server configurations.
74.
▲
by
Scott_Helme_
11y ago
A lot of advice online, including my own, recommends that once you start enforcing a policy you keep the max-age quite short for a period of time. The report-only mode is helpful in identifying issues but given the nature of what HPKP is an
75.
▲
by
Scott_Helme_
11y ago
I agree, hopefully the majority will see benefit in it. It's intended as more of a way to educate rather than a definitive security assessment.
76.
▲
by
Scott_Helme_
11y ago
Glad it could help!
77.
▲
by
Scott_Helme_
11y ago
To be honest, most of the reports I get for my sites aren't legitimate issues. Malware on the endpoint makes changes to pages (like inserting ads) that generate reports, certain browser features trigger changes that cause reports. Ther
78.
▲
by
Scott_Helme_
11y ago
Yes, sorry that wasn't clear. I scanned the sites in groups of 4,000. The x axis is each group in descending order from the top of the Alexa list to the bottom.
79.
▲
by
Scott_Helme_
11y ago
Interesting, I don't use Firefox enough to have noticed this. Would it be possible to whitelist this functionality in your CSP in the short term without adversely affecting the strength of your policy?
80.
▲
by
Scott_Helme_
11y ago
Sadly nly is right. The only other option to change this is the ngx_headers_more module, but that still requires a rebuild. I suppose that way you at least get a little more functionality for your troubles.
81.
▲
by
Scott_Helme_
11y ago
I'm going to be doing some blogs in the coming weeks on how to use hashes and nonces to whitelist inline script. Hopefully, this will make introducing CSP a little easier. I also have some tools in the making that will help in this reg
82.
▲
by
Scott_Helme_
11y ago
If you like, you could also add reporting to your CSP and get live feedback on it with https://report-uri.io It's free to sign up and use.
83.
▲
by
Scott_Helme_
11y ago
It's worth pointing out that you can replace the functionality of the X-Frame-Options header with Content-Security-Policy using the frame-ancestors directive if you want to: https://scotthelme.co.uk/csp-cheat-sheet/