We scanned 7,040 directory-listed U.S. local-business websites for security headers. Half met none of seven criteria. Full report, data and code.
15 comments
stargrazer6 days ago
So.. you've written up what you checked, and what didn't match what ever criteria you had.
But.. what does it mean? Why enforce certain headers? Why enforce certain options? There is a section which kinda looks at this, but not really.
You have a bunch of links at the end for resources, but why not just provide the rationale for each rule or option inclusion in the article as well? What does each prevent or allow and why?
aetherspawn6 days ago
It’s ridiculous that the answer to a secure web is for everyone to sprinkle the magic salt and not something on the browser side
rackcrunch6 days ago
Referrer-Policy shows it can work. When the header is missing, browsers fall back to strict-origin-when-cross-origin. 86.6% of the sites we scanned don't send it, and we didn't count that as a failure for that reason. The other headers don't have a safe default like that yet.
axospaxos6 days ago
That sounds more like it is a condemnation of all these other headers that can't work for 86.6% of sites by requiring nothing.
alserio6 days ago
we'd need an epoch like reset to good defaults
aetherspawn6 days ago
For important issues like security - just break the web, it will adjust.
GaProgMan6 days ago
And if any of the websites use .NET, they can get almost all of the recommended security headers in one line by using a NuGet package I created: https://gaprogman.github.io/OwaspHeaders.Core/
n4pw01f6 days ago
Nice work! You gave me something to fix!!
tumdum_6 days ago
Sadly non of it was written by a human being.
rackcrunch6 days ago
Fair. The study is backed by a human being who stands behind every number. And absolutely, use whatever tool you like.
rackcrunch6 days ago
Thanks, glad it helped!
fitsumbelay6 days ago
for static sites on a VPS it's fair to expect the host to provision these, yes?
aetherspawn6 days ago
No, not for a VPS. They are configured at the web server. If you mean CDN, you might be able to use a _headers file or similar to add. Cloudflare can definitely do it.
wink6 days ago
for static sites... it's not that I would call them useless, but most are just not very critical. Clickjacking and any cookie attacks on a site without cookies is pretty useless most of the time.
Read the full thread on Hacker News →
Related stories
- The Verge · 0 points · 2 days ago
- Hacker News · 1 points · 3 days ago
- Forging 1024-bit RSA signatures in nearly SNFS timeeprint.iacr.orgLobsters · 7 points · 6 days ago
- Ars Technica · 0 points · 9 days ago
- On Improvements of Low-Deterministic Security (2016)pp.ipd.kit.eduLobsters · 2 points · about 8 years ago
- Hacker News · 1 points · 4 days ago