Good morning Barbados! ๐คฉ๐ ๐๏ธ๐ง๐ง
01.12.2025 09:49 โ ๐ 2 ๐ 0 ๐ฌ 0 ๐ 0@scotthelme.bsky.social
Hi, I'm Scott Helme, a Security Researcher, Entrepreneur and International Speaker. I'm the creator of Report URI and Security Headers, and I deliver world renowned training on Hacking and Encryption. https://scotthelme.co.uk
Good morning Barbados! ๐คฉ๐ ๐๏ธ๐ง๐ง
01.12.2025 09:49 โ ๐ 2 ๐ 0 ๐ฌ 0 ๐ 0Join me tomorrow for this webinar on CSP Integrity, our most cutting-edge feature for client-side security!
report-uri.com/webinar/csp_...
Do you want to quickly and easily know if all of your JavaScript assets across your site are using SRI? Now you can!
Announcing the open-beta of Integrity Policy!
scotthelme.co.uk/integrity-po...
No, the crash reports are quite limited in that regard. Their main goal is to let you know something is happening that you might have no other way to find out about.
27.10.2025 15:04 โ ๐ 3 ๐ 0 ๐ฌ 0 ๐ 0A strange Chromium bug triggered by a CSP directive that caused a crash went unsolved for months, and we had the data right in front of us in Report URI to explain why it was happening ๐ฎ www.troyhunt.com/how-we-almos...
27.10.2025 09:11 โ ๐ 17 ๐ 3 ๐ฌ 1 ๐ 0We provide information on the steps for remediation, and link out to verified sources of information on the vulnerability if you'd like more information.
29.09.2025 11:11 โ ๐ 2 ๐ 0 ๐ฌ 0 ๐ 0Along with identifying the JS files on your site, we can also cross-check them against our database of Known Vulnerabilities, and flag when you're loading JS with serious issues!
29.09.2025 11:11 โ ๐ 0 ๐ 0 ๐ฌ 1 ๐ 0Of course, this also means that you can detect when/if those JS files change, as they will start reporting a new hash. This is a great way to be able to monitor for undesirable changes to 3rd-party dependencies.
29.09.2025 11:11 โ ๐ 0 ๐ 0 ๐ฌ 1 ๐ 0We've already built a database of almost 13,000,000 fingerprints that we have verified, meaning we can reliably identify files loading on your site.
29.09.2025 11:11 โ ๐ 0 ๐ 0 ๐ฌ 1 ๐ 0You can now fingerprint JS running on your site with a cryptographically secure hash function and have that data sent to report-uri.com This is native browser functionality, so there is no code to deploy anywhere!
29.09.2025 11:10 โ ๐ 0 ๐ 0 ๐ฌ 1 ๐ 0We've just launched an awesome new feature at report-uri.com! You can now collect Integrity Metadata, natively from the browser, for JavaScript running on your site!
It takes seconds to deploy, so read the thread for the amazing benefits this will bring.
scotthelme.co.uk/capture-java...
New dates! Practical TLS and PKI Training - Nov 10-13 2025.
And if you can't wait that long, we still a few tickets for the training next week. Join us! From @ivanristic.com and with @scotthelme.bsky.social
www.feistyduck.com/training/pra...
It has, but there's always an element of ongoing work. It's not just extensions, but corporate proxies/firewalls, AV software on the client, and anything that can interfere with the page.
Our filtering has become pretty good ๐
To celebrate, we've just launched a seriously cool public dashboard that gives heaps of insight into our traffic! Check it out, and there is something in there I've wanted to build for a very long time:
scotthelme.co.uk/trillion-wit...
This is absolutely unbelievable!!!
We've just passed through 2 trillion events processed at
Report URI!!! report-uri.com
๐คฏ๐ฅณ๐
New dates! Practical TLS and PKI, Sep 22-25. From @ivanristic.com, based on the Bulletproof book, with lots of exercises to give you hands-on experience. Your teacher will be @scotthelme.bsky.social. And now is a good time to grab an Early Bird ticket ($300 off).
www.feistyduck.com/training/pra...
Our final TLS and PKI Training before the summer will take place on 3-6 June. Four half-days, with real-world exercises to work on during the training and afterwards. With @scotthelme.bsky.social and from @ivanristic.com Join us! www.feistyduck.com/training/pra...
15.05.2025 13:31 โ ๐ 2 ๐ 1 ๐ฌ 0 ๐ 0Four weeks until the next Practical TLS and PKI Training - Join @scotthelme.bsky.social on June 3-6 to learn how to deploy secure servers and design secure web applications. Four half days, Pacific Time AM. From @ivanristic.com.
www.feistyduck.com/training/pra...
Certificate renewal should be fully automated by then, and ideally by now already. Once renewal is automated, how often you renew really doesn't matter any more. I have no idea when any of my certificates renew, they just do it!
22.04.2025 14:20 โ ๐ 1 ๐ 0 ๐ฌ 2 ๐ 0I might like this version of the graph more! ๐ค
22.04.2025 14:19 โ ๐ 0 ๐ 0 ๐ฌ 0 ๐ 0Well, hopefully, you wouldn't leave it so close to expiry, I'd probably recommend every 30 days.
22.04.2025 14:15 โ ๐ 1 ๐ 0 ๐ฌ 1 ๐ 0Here's what that looks like when viewing the full history, which shows we recently stalled out on our progress to shorter certificates, and even these new deadlines are a much reduced rate of progress:
22.04.2025 13:42 โ ๐ 1 ๐ 0 ๐ฌ 1 ๐ 0Straight to the point, here is the schedule for the reduction in certificate lifetimes!
March 15th 2026: All new certificates capped at 200 days validity
March 15th 2027: All new certificates capped at 100 days validity
March 15th 2029: All new certificates capped at 47 days validity!
Oh yeah! Shorter certificates are coming!!
๐๐๐โ
scotthelme.co.uk/shorter-cert...
I've had a little fun with my Tesla Powerwalls, Home Assistant and Teslemetry over the holiday weekend!
scotthelme.co.uk/hacking-my-t...
No, it hooks up to my DNS provider and sets DNS TXT records, I don't use the HTTP validation mechanism.
04.03.2025 09:38 โ ๐ 1 ๐ 0 ๐ฌ 1 ๐ 0Even if I switch to cellular data, or VPN to a new IP address altogether, they still donโt work. This is an example with my email signature, but no images work at all.
07.02.2025 09:58 โ ๐ 1 ๐ 0 ๐ฌ 0 ๐ 0It doesn't seem like rate limits make sense, and the status codes we're getting for images in our emails is a 403, not something like a 429 as I'd expect. We also don't send/receive that many emails so rate limits again don't sound very likely?
07.02.2025 09:57 โ ๐ 1 ๐ 0 ๐ฌ 1 ๐ 0This is pretty nuts, we've been having issues with our @fastmail.com emails where images aren't working...
They're suggesting rate limits at @cloudflare.social are the issue, but how much sense does that make?
Either way, Fastmail recommendation is to stop using their app and web interface?!
We've made a few more improvements to report-uri.com over the last week!
scotthelme.co.uk/stronger-tha...