TLS 1.0 and 1.1 are dead: why your old protocols are a liability
TLS 1.0 and 1.1 were retired years ago, but plenty of hosts still accept them. Leaving them on is a quiet liability — here is what to support instead.
Web security, secret leaks, misconfigurations and how to earn trust — straight from the scanner team.
TLS 1.0 and 1.1 were retired years ago, but plenty of hosts still accept them. Leaving them on is a quiet liability — here is what to support instead.
Clickjacking loads your real site inside an invisible frame so users click things they cannot see. The defense is one header — here is how to set it right.
An AWS access key has a recognizable shape, which makes it easy for bots to spot. Here is where they leak from and what typically happens right after.
When an AI assistant writes most of your backend, the responsibility question gets blurry. The answer is simpler than it feels — and it is on you, in a good way.
A security scanner is in a position of trust. Here is exactly what ours does and does not do — only your domain, no third-party probing, no plaintext secrets stored.
We scanned 5 popular security scanners with our own engine. None had a critical flaw — but every one leaked something Medium. Here is what, and why it matters.
You are about to deploy. Before you do, run down this short list — the handful of things that get found and exploited first on a fresh site.
A badge that can only ever say pass is a sticker. We publish the report behind every badge — including red ones — because verifiable beats impressive.
Your report lists what passed, what failed, and how bad each issue is. Here is how to read it without panic, and the order to fix things in.
Your app ships dozens of packages you never chose. When one gets hijacked, you ship the attack too. Here is the pattern, the big recent incidents, and the defenses.
A practical reference: the security headers worth setting, sane values for each, and exactly what every line buys you. Copy it, adjust the CSP, ship it.
The padlock only means encrypted, not strong. Real TLS security depends on three things: which protocols you accept, which ciphers you offer, and your certificate's health.