Category: Scott Helme

Goodbye, old friend 👋🔒

It's been a really long time coming, but, the end is finally here for the padlock icon in the address bar! 🔒🚫 A Long Road Wow, where do I start?! Whilst the dawn of the encrypted Web was in 1994,…

Strengthening security on my Apple account!

Apple announced some awesome, new security features last year and they were due to land in 2023. Well, it's 2023, and they've landed! Apple are bringing some mega security features in 2023! https://t.co/iYi020xt53 — Scott Helme (@Scott_Helme) December 7, 2022…

Strengthening security on my Apple account!

Apple announced some awesome, new security features last year and they were due to land in 2023. Well, it's 2023, and they've landed! Apple are bringing some mega security features in 2023! https://t.co/iYi020xt53 — Scott Helme (@Scott_Helme) December 7, 2022…

Report URI Penetration Test 2022

Another year of development, new features, bug fixes and progress has been made so that means it's time for our annual penetration test over at Report URI! Penetration Tests As is tradition, Report URI has just undergone another penetration test…

The M140i project post – Part 17

It's been a while since I've had time to work on my car and then to find time to write up what it is that I've been up to, but, it's time for another post! The Series The last post…

New pricing for Report URI

Report URI has been running as a publicly available service for over 7 years now and this will be the first ever change to our pricing. Don't worry though, if you're an active subscriber, this won't have any impact on…

Report URI has a new look!

It's been a long time since the main website for Report URI got any real attention, with all of our efforts being focused on developing new features and improving existing ones. The time has finally come for a bit of…

Implementing all the Stripe things for Report URI

We've recently pushed some changes to the Report URI billing processes that will result in a better experience for our users, give us less lines of code to maintain and simplify our tax handling! What are the changes? Before I…

Implementing all the Stripe things for Report URI

We've recently pushed some changes to the Report URI billing processes that will result in a better experience for our users, give us less lines of code to maintain and simplify our tax handling! What are the changes? Before I…

Another free CA to use via ACME!

I've been really happy over the years to see more CAs start to offer certificates via ACME and that those CAs have some kind of free certificate offering. Let's Encrypt is awesome and I've used them since the beginning, but…

The M140i project post – Part 16

It's been a while since I published something about my car and it's another big post! I've talked about alcohol based fuels before, like my methanol injection post or my ethanol fuel blending post, but this time I'm going a…

Top 1 Million Analysis – June 2022

Thanks to the sponsorship provided by Venafi for this post, we have another Top 1 Million Analysis just 6 months after the last one in November 2021! Let's take a look at what's changed in the last 6 months and…

Increasing entropy in our CSP nonces

This article has been indexed from Scott Helme I've talked many times about CSP and CSP nonces, the easy way to control JavaScript on your page, but someone recently pointed out an area we could improve. Report URI needed to…

Re-bloom! Pwned Passwords v8

This article has been indexed from Scott Helme After the recent release of the Pwned Passwords v8 dataset, it was time to update my Bloom Filter implementation of Pwned Passwords! Bloom Filters If you aren't familiar with what a Bloom…

Re-bloom! Pwned Passwords v8

This article has been indexed from Scott Helme After the recent release of the Pwned Passwords v8 dataset, it was time to update my Bloom Filter implementation of Pwned Passwords! Bloom Filters If you aren't familiar with what a Bloom…

Can you get pwned with CSS?

This article has been indexed from Scott Helme I recently started to consider changing the grading criteria on Security Headers which isn't something that happens very often. I wanted to make a change that would result in more sites achieving…

Projects I Support

This article has been indexed from Scott Helme As we roll further into 2022, I wanted to outline the projects and other activities in the community that I support in the hope that it might inspire you to consider doing…

Projects I Support

This article has been indexed from Scott Helme As we roll further into 2022, I wanted to outline the projects and other activities in the community that I support in the hope that it might inspire you to consider doing…

Top 1 Million Analysis – November 2021

This article has been indexed from Scott Helme Wow! It's been quite a while since I've had time to do my regular analysis of security in the Top 1 Million site, but it's happening again! As it's been over 18…

Report URI Penetration Test 2021

This article has been indexed from Scott Helme Wow, where did that last year go?! It's time for our annual penetration test again over at Report URI and just like we did last year, we'll be publishing the entire report,…

Sketchy Pwned Passwords

This article has been indexed from Scott Helme After playing with some more probabilistic data structures and talking about Count-Min Sketch, I wanted to expand on my previous work with the Pwned Passwords data set. This is quite an interesting…

When Pwned Passwords Bloom!

This article has been indexed from Scott Helme I recently wrote about Bloom Filters, the hugely space efficient, probabilistic data structures, and how great they can be. I wanted to create a demonstration of just how useful they could be…

Working around expired Root Certificates

This article has been indexed from Scott Helme Should clients care about when a Root Certificate expires? That's a bit of an odd question, and the first time I asked myself this question, the answer was a resounding 'yes, of…

Let’s Encrypt Root Expiration – Post-Mortem

This article has been indexed from Scott Helme Well, the Internet Apocalypse came and went! Due to the recent expiration of the Let's Encrypt intermediate and root certificates, I saw more widespread issues than I was expecting, but on different…

Let’s Encrypt’s Root Certificate is expiring!

This article has been indexed from Scott Helme On 30th September 2021, the root certificate that Let's Encrypt are currently using, the IdentTrust DST Root CA X3 certificate, will expire. You may or may not need to do anything about…

The M140i project post – Part 15

This article has been indexed from Scott Helme I took a bit of a break from writing up my work on the M140i but I'm back and there are a few things I want to cover! This post is going…

The danger of open redirects!

This article has been indexed from Scott Helme Like everyone else, I get a lot of spam emails that range from downright annoying through to deceptive phishing emails that are really dangerous. Today I got one of the latter and…

The danger of open redirects!

This article has been indexed from Scott Helme Like everyone else, I get a lot of spam emails that range from downright annoying through to deceptive phishing emails that are really dangerous. Today I got one of the latter and…

Creating a Home Alarm System with Home Assistant

This article has been indexed from Scott Helme I've not talked too much about my Home Assistant installation but it's absolutely amazing and I've just done something even more awesome with it. Creating a home alarm system was much easier…

Setting up HTTPS for Home Assistant

This article has been indexed from Scott Helme I absolutely love Home Assistant and if you follow me on Twitter then you will have probably seen me talking about various awesome things that I do with HA. This blog post…

Setting up HTTPS on the UniFi Protect NVR

This article has been indexed from Scott Helme I recently wrote about setting up a new CCTV system for my house using the UniFi Protect range and like all good bits of kit, it comes with a web interface. Using…

What the FLoC?!

Read the original article: What the FLoC?! There have been quite a few mentions of FLoC recently and several people have been providing various links, bits of information and questions about the new feature. Whilst it's still quite a new…

What the FLoC?!

Read the original article: What the FLoC?! There have been quite a few mentions of FLoC recently and several people have been providing various links, bits of information and questions about the new feature. Whilst it's still quite a new…

Transparency about Data Protection at Report URI

Read the original article: Transparency about Data Protection at Report URI When I started building Report URI almost 6 years ago, it was a small project operated by just me and handled very little data. With 6 years behind us…

Transparency about Data Protection at Report URI

Read the original article: Transparency about Data Protection at Report URI When I started building Report URI almost 6 years ago, it was a small project operated by just me and handled very little data. With 6 years behind us…

Enabling COOP and COEP reports on Report URI

Read the original article: Enabling COOP and COEP reports on Report URI A couple of months ago I talked about a few new features coming to a browser near you that included both COOP and COEP. With the latest version…

The M140i project post – Part 14

Read the original article: The M140i project post – Part 14 With a significant amount of work having taken place on my car over the last year or so, a lot of effort also goes into making sure nothing goes…

Supercharging your DNS with Cloudflare for Teams!

Read the original article: Supercharging your DNS with Cloudflare for Teams! I was recently quite surprised to be introduced to an idea about using Cloudflare for Teams to look after my personal DNS. I’ve never used Cloudflare for Teams before…

The M140i project post – Part 13

Read the original article: The M140i project post – Part 13 In Part 11 and Part 12 I looked at the introduction of alcohol based fuel with my Water/Methanol Injection system and Ethanol fuel blending. In Part 13 we’re going…

Report URI Penetration Test

Read the original article: Report URI Penetration Test In line with our constant desire to improve and offer the best service we can, Report URI recently went through an independent penetration test as many other companies and organisations do. Unlike…

Report URI Penetration Test

Read the original article: Report URI Penetration Test In line with our constant desire to improve and offer the best service we can, Report URI recently went through an independent penetration test as many other companies and organisations do. Unlike…

The M140i project post – Part 12

Read the original article: The M140i project post – Part 12 Following on from the wild idea of injecting water and methanol into my engine in Part 11, Part 12 is going to have a considerable focus on more alcohol…

Déjà vu – macOS hits OCSP hurdles

Read the original article: Déjà vu – macOS hits OCSP hurdles Regular readers will have seen me talk about OCSP many times before and some of those times are going back quite a number of years. That’s why it came…

The M140i project post – Part 11

Read the original article: The M140i project post – Part 11 This is going to be a big one and I’m super excited! In this post I’m only going to be talking about one thing but it’s pretty significant in…

The M140i project post – Part 10

Read the original article: The M140i project post – Part 10 Part 10?! When I started writing this series I did not expect to hit Part 10 and the good news for those appreciating these blog posts is that there’s…

Let’s Encrypt postpone the ISRG Root transition

Read the original article: Let’s Encrypt postpone the ISRG Root transition I was looking forward to something happening this month in the world of PKI that has had to be postponed for the 3rd time. Let’s Encrypt were going to…

Goodbye Feature Policy and hello Permissions Policy!

Read the original article: Goodbye Feature Policy and hello Permissions Policy! I talked about Feature Policy almost 2 years ago and it has seen great adoption since then. As things have progressed  a name change has been proposed and accepted…

The M140i project post – Part 9

Read the original article: The M140i project post – Part 9 After another short break from writing about the car project it’s time to hit it again with Part 9 and quite a few items that you don’t need to…

Cross-Signing and Alternate Trust Paths; How They Work

Read the original article: Cross-Signing and Alternate Trust Paths; How They Work In my last couple of posts about CAs and Root Certificates I’ve talked about something called Alternate Trust Paths. As a result, many people have asked me questions…

Cross-Signing and Alternate Trust Paths; How They Work

Read the original article: Cross-Signing and Alternate Trust Paths; How They Work In my last couple of posts about CAs and Root Certificates I’ve talked about something called Alternate Trust Paths. As a result, many people have asked me questions…

Launching a brand new theme!

Read the original article: Launching a brand new theme! I host my blog on Ghost and they’ve announced some cool new features recently that I’ve wanted to use but never quite had time to implement. Well, that recently changed so…

Launching a brand new theme!

Read the original article: Launching a brand new theme! I host my blog on Ghost and they’ve announced some cool new features recently that I’ve wanted to use but never quite had time to implement. Well, that recently changed so…

The M140i project post – Part 7

Read the original article: The M140i project post – Part 7 Digging into the 7th part of this series now and it’s time to visit the chassis and handling again. Making a car go fast isn’t just about more power,…

Setting up HTTPS on the UDM Pro

Read the original article: Setting up HTTPS on the UDM Pro I recently upgraded my home network to the latest generation of Ubiquiti hardware and with new hardware comes the requirement to set a couple of things up again, things…

Setting up HTTPS on the UDM Pro

Read the original article: Setting up HTTPS on the UDM Pro I recently upgraded my home network to the latest generation of Ubiquiti hardware and with new hardware comes the requirement to set a couple of things up again, things…

The M140i project post – Part 6

Read the original article: The M140i project post – Part 6 I can’t believe we’re on Part 6 of this series now and things are still moving along at an awesome pace! Time to get hands on with a few…

My Ubiquiti Home Network – V2

Read the original article: My Ubiquiti Home Network – V2 I’ve been using Ubiquiti networking equipment at home for quite some time now and I’ve honestly not had a single complaint to make. Recently, Ubiquiti reached out to me and…

My Ubiquiti Home Network – V2

Read the original article: My Ubiquiti Home Network – V2 I’ve been using Ubiquiti networking equipment at home for quite some time now and I’ve honestly not had a single complaint to make. Recently, Ubiquiti reached out to me and…