TLS/SSL
Is my SSL/TLS actually secure? A plain-English checklist
The padlock only means encrypted, not strong. Real TLS security depends on three things: which protocols you accept, which ciphers you offer, and your certificate's health.
Tag
The padlock only means encrypted, not strong. Real TLS security depends on three things: which protocols you accept, which ciphers you offer, and your certificate's health.
You have HTTPS — but the first plain-HTTP request is still a weak point. HSTS closes it by telling the browser to never speak HTTP to your site again.