Security headers on 4,688 small-business websites: 49.7% met none of 7 criteria
15 points by terrybyte 2 hours ago | 12 comments

stargrazer 40 minutes ago
So.. you've written up what you checked, and what didn't match what ever criteria you had.

But.. what does it mean? Why enforce certain headers? Why enforce certain options? There is a section which kinda looks at this, but not really.

You have a bunch of links at the end for resources, but why not just provide the rationale for each rule or option inclusion in the article as well? What does each prevent or allow and why?

reply
rackcrunch 18 minutes ago
[flagged]
reply
aetherspawn 58 minutes ago
It’s ridiculous that the answer to a secure web is for everyone to sprinkle the magic salt and not something on the browser side
reply
rackcrunch 36 minutes ago
Referrer-Policy shows it can work. When the header is missing, browsers fall back to strict-origin-when-cross-origin. 86.6% of the sites we scanned don't send it, and we didn't count that as a failure for that reason. The other headers don't have a safe default like that yet.
reply
axospaxos 26 minutes ago
That sounds more like it is a condemnation of all these other headers that can't work for 86.6% of sites by requiring nothing.
reply
rackcrunch 17 minutes ago
[dead]
reply
alserio 45 minutes ago
we'd need an epoch like reset to good defaults
reply
aetherspawn 34 minutes ago
For important issues like security - just break the web, it will adjust.
reply
GaProgMan 52 minutes ago
And if any of the websites use .NET, they can get almost all of the recommended security headers in one line by using a NuGet package I created: https://gaprogman.github.io/OwaspHeaders.Core/
reply
n4pw01f 2 hours ago
Nice work! You gave me something to fix!!
reply
tumdum_ 58 minutes ago
Sadly non of it was written by a human being.
reply
rackcrunch 24 minutes ago
Fair. The study is backed by a human being who stands behind every number. And absolutely, use whatever tool you like.
reply
rackcrunch 37 minutes ago
Thanks, glad it helped!
reply
fitsumbelay 38 minutes ago
for static sites on a VPS it's fair to expect the host to provision these, yes?
reply
rackcrunch 18 minutes ago
[dead]
reply