Remove hsts-from-top-to-bottom-or-gtfo
article thumbnail

HSTS From Top to Bottom or GTFO

Troy Hunt

Possibly, although a saving grace would have been Chrome's red indicator once I started typing the password (although in my case, I would have tried to autofill from 1Password and I'd have 2FA to protect me if someone else grabbed it, but you get the point). And why is there no HSTS which would have avoided this situation altogether?

article thumbnail

Weekly Udpate 164

Troy Hunt

It's a late, early in the day, hazy, bush-firey Aussie weekly update with a whole bunch of various bits and pieces of interest from throughout the week. Finally - free SSL on the Azure app service for custom domains! (non-apex just read it and shake your head.) LinkedIn now has a security.txt file! (if

IT 75
article thumbnail

Weekly Update 164

Troy Hunt

It's a late, early in the day, hazy, bush-firey Aussie weekly update with a whole bunch of various bits and pieces of interest from throughout the week. Finally - free SSL on the Azure app service for custom domains! (non-apex just read it and shake your head.) LinkedIn now has a security.txt file! (if

IT 46