Mozilla has released a free tool that allows website developers and administrators to determine if they are using all available security technologies at their full potential.
The tool, named "Observatory," was developed by Mozilla Information Security Engineer April King in an effort to help the organization test its own domains. Observatory has now been made available to everyone along with its source code.
Observatory performs nearly a dozen tests, including Content Security Policy (CSP), Contribute.json, cookies, cross-origin resource sharing (CORS), HTTP Public Key Pinning (HPKP), HTTP Strict Transport Security (HSTS), redirections, subresource integrity, and X-Content-Type-Options, X-Frame-Options and X-XSS-Protection headers.
[...] "Observatory is currently a very developer-focused tool, and its grading is set very aggressively to promote best practices in web security. So if your site fails Observatory's tests, don't panic — just take a look at its recommendations and consider implementing them to make your site more secure," King said.
(Score: 2, Interesting) by barrahome on Monday August 29 2016, @06:43AM
The tool is useless. They said i don't redirect to SSL and i DO IT, tested that over a millon times, for sure they are expecting an HTML or Javascript redirect. Too bad they don't know how to properly do tests.
(Score: 2) by arslan on Monday August 29 2016, @06:52AM
Yea.. pretty lame. I ran it against SN and it says no cookie detected which is inaccurate. I can see the SN cookies when I check my browser.
(Score: 1) by barrahome on Monday August 29 2016, @06:59AM
Let's Boycott Mozilla Observatory, we can ask them to rename it to "Mozilla Unservatory" or something more compelling.
(Score: 0) by Anonymous Coward on Monday August 29 2016, @07:27AM
Yea.. pretty lame. I ran it against SN and it says no cookie detected which is inaccurate. I can see the SN cookies when I check my browser.
I don't get cookies. And I browse with firefox's "cookies" window up in the corner of my monitor all the time so I am acutely aware of which sites hand out cookies and when.
But I don't log in to soylent either.
Sounds like yet another problem with the nut behind the wheel.
(Score: 3, Informative) by NCommander on Monday August 29 2016, @11:20AM
SN only cookies if you log in.
Still always moving