Joined May 2015
34 Photos and videos
Did somebody say Security Headers?! 💙
Look who I saw at the @AppSec_Village ??? My favorite security headers fan, @Scott_Helme !!!
1
1
5
3,105
Security Headers retweeted
Can anyone tell me the story behind the HSTS max-age value on Amazon? 🤔 There’s got to be a reason behind that! @amazon @AWSSecurityInfo @securityheaders securityheaders.com/?q=amazo…
4
2
12
6,791
We’re at @BlackHatEvents with @probely! 🔒 Stop by booth #1486, try out a free scan of your website, grab some cool swag and meet our founder @Scott_Helme 😎 prbly.us/3Ow4qNi
2
2
9
1,882
👀
2
16
3,729
Security Headers retweeted
4 May 2023
Come and find us at @NDC_Conferences Oslo for our first ever vendor exhibit! Meet our founder, see a product demo, enter our hacking competition or watch our artist create your swag live on the stand! It's going to be epic, we'll see you there 😎 report-uri.com/event/ndc_osl…

1
5
10
12,953
Security Headers retweeted
28 Mar 2023
Safari 16.4 is bringing support for the Reporting API! This means reports can be sent out-of-band asynchronously, and, we’re getting some new reports too. ✅ Reporting API ✅ COEP violation reporting ✅ COOP/COEP nav violation reporting webkit.org/blog/13966/webkit…
1
3
8
3,176
Security Headers retweeted
A few people reached out to say they couldn't get their corporate card or approval in time so I've extended this code for another 7 days! Apparently when you work for a company there's like "processes" and stuff! Who knew?! 😅 Use 15FORLIFE at checkout to get 15% off for life!!
2
7
1,885
Security Headers retweeted
This is really interesting research and I wanted to know if I could expand upon it using Content Security Policy and reporting via @reporturi. I've just created inappbrowsercsp.com/ to do exactly that!

18 Aug 2022
🔥 New Post: Announcing InAppBrowser - see what JavaScript commands get injected through an in-app browser 👀 TikTok, when opening any website in their app, injects tracking code that can monitor all keystrokes, including passwords, and all taps. krausefx.com/blog/announcing…
6
17
42
Security Headers retweeted
I'm considering changing the grading criteria on @securityheaders to allow an A grade with a CSP that contains unsafe-inline in the style-src directive. What are your thoughts?
37% Yes, allow A
25% No, keep as it is
38% Show results
436 votes • Final results
12
8
20
Security Headers retweeted
1 TRILLION REPORTS!!!1!!1! 🌟✨🥳🥂🍾
7
5
94
150,000,000 scans?! A huge thanks to our sponsor @probely who have supported us through this milestone and made it possible! 😱💪🔥🎉❤🌍🔒
3
5
33
We're *fast* approaching 150,000,000 scans!!! Big thanks to our sponsor @probely, who continue to support us and make this all possible 🤩
1
13
We will now maintain a public list of our origin server IP addresses for both IPv4 and IPv6 scans: securityheaders.com/.well-kn… securityheaders.com/.well-kn…

1
3
24
A *huge* thanks to @probely for their continued sponsorship which allows for development work on new features like this and our ongoing operation as a free service ❤
COEP COOP CORP CORS CORB - CRAP that's a lot of new stuff! scotthelme.co.uk/coop-and-co…
1
8
We've powered through 110,000,000 free scans and we're super grateful to have @probely sponsoring us again this month! Check them out and say thanks probely.com/r/hS7 🌍🔒💚
4
13