
HSTS preload: Sending the Word Is Not Being on the List
This morning I lined up the HSTS headers of my own domains. All of them are mine, I configured every...
Sep 13, 202613 min read1 reactions0 comments
Tag archive

This morning I lined up the HSTS headers of my own domains. All of them are mine, I configured every...
Plain-English guide to security headers: what they are, the 5 every small site needs (CSP, HSTS, and more), and exact code to add them.
From an F grade to a hardened A: deploy HSTS, nosniff, frame protection and Permissions-Policy immediately, then roll out Content-Security-Policy in three safe stages - with nginx and Apache configs.

Understand HSTS certificate and learn how to level up your website’s security using HTTP Strict...
If you happen to have problems with OWASP ZAP using Chrome and visiting a site that supports HSTS in...