The answer to the question above is a resounding “YES!” if you don’t have Strict-Transport-Security (HSTS) enabled. Lately, I’ve seen a lot of sites operating without HSTS enabled and I’m not sure have good reason as to why.This is particularly troublesome because setting HSTS up on your site is such a low-effort, high-impact task. Considering […]

Read More » HSTS: Is Your Security Policy Leaving Users Vulnerable?

Want a free, no-commitment audit of your website to check your cookie security? Schedule Consultation A lot of time is spent on certain security features. For instance, things like password strength, multi-factor authentication and encryption usually dominate the discussion. And for good reason; security isn’t optional. But there is a softer target that attackers go […]

Read More » Secure Cookies: How the Cookie Crumbles in 3 Ways