Remove tag e-privacy-directive
article thumbnail

Is India's Aadhaar System Really "Hack-Proof"? Assessing a Publicly Observable Security Posture

Troy Hunt

But claiming the service is "hack-proof", that's something I definitely have an issue with. Just as in my post on NatWest last month , that entry point must be as secure as possible or else everything else behind there gets put at risk. The fix for this risk is HTTP Strict Transport Security or HSTS for short.

Security 111