Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I must admit it is a little ironic that your site doesn't use the security headers you advocate.


The irony is not lost on me, we have a saying in the Netherlands "the carpenters doors are the creakiest". Also we don't use them all the time yet even for customers, this blog post (and an accompanying internal training next week) is meant to remedy that.


Indeed they're. Looks like comments on your blog don't work. And there's no RSS feed :(


Tell me, which of the four headers he talked about --- CSP, XFO, XCTO, and HSTS --- are going to cause serious problems for a blog?


CSP would be useful defense in depth if the blog has comments and an admin interface on the same domain or subdomain within TLD/public suffix — XSS in a comment could lead to session fixation/hijacking.

XFO also might be useful if the blog has predictable layout of the admin interface — logged-in blog admin could be tricked via clickjacking to perform potentially undesirable actions.


The directory entries at http://ibuildings.nl/robots.txt suggest that they're hosting much more than a blog on that domain.

Edit: As others pointed it out, it's a Drupal installation. Trusting Drupal to be 100% safe in regards to malicious attacks is not a good idea. I know this is nitpicking, it is however still ironic.

http://www.cvedetails.com/vulnerability-list/vendor_id-1367/...


It's a drupal-powered site. It's no different from WP though IMO.


At least he should enable XFO if he doesn't want to be framed.

His HTTPS endpoint is not trusted by the browser, either self-signed or missing some intermediary cert... If he wants to enable the contact form for business inquiry or personal inquiry, might be worthwhile to get some $10 cert? If he already ahve gotten that far to get a 443 port enabled.

XCTO is pretty cheap to enable and doesn't hurt. The only problem is IRRC IE has a different MIME list then Firefox and Chrome.

It's pretty cheap to enable some of these security headers, just as it is relatively easy to disable some of the server-type headers (x-powered-by e.g, which apparently he doesn't have it exposed I think)




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: