Remove https-is-easy
article thumbnail

HTTPS Is Easy!

Troy Hunt

HTTPS is easy! If you are a tech pro and you want to go deeper on HTTPS, have a browse back through the dozens of posts on the SSL tag or go and watch 3 and a half hours of Pluralsight training on the subject. I built a little demo site and embedded all the videos in it over at HTTPSIsEasy.com.

article thumbnail

Here's Why Your Static Website Needs HTTPS

Troy Hunt

Even the government has been pushing to drive adoption of HTTPS for all sites, for example in this post by the National Cyber Security Centre in the UK : all websites should use HTTPS, even if they don't include private content, sign-in pages, or credit card details. Is it needed? Does it do any good? What's it actually protecting?

DNS 277
Insiders

Sign Up for our Newsletter

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

article thumbnail

HSTS From Top to Bottom or GTFO

Troy Hunt

About 80% of all web pages are loaded over an HTTPS connection , browsers are increasingly naggy when anything isn't HTTPS and it's never been cheaper nor easier to HTTPS all your things. And hey, it's free, easy and one of the best defences going for precisely this threat.

Passwords 219
article thumbnail

Understanding & Defending Against Adversary-in-the-Middle (AiTM) Attacks

Duo's Security Blog

Oftentimes, these proxy sites will use HTTPS, so they will still show the lock icon in most browsers. HTTPS: HTTPS, or Hypertext Transfer Protocol Secure, is a secure version of HTTP. HTTPS: HTTPS, or Hypertext Transfer Protocol Secure, is a secure version of HTTP. HTTPS is never broken.

article thumbnail

How to hack the Airbus NAVBLUE Flysmart+ Manager

Security Affairs

The ATS is a security mechanism that forces the use of the HTTPS protocol, which means that disabling it could open to tamper with and decrypt the traffic. “It’s quite easy to identify pilots in layover hotels. It’s also fairly easy to identify the airline and therefore the suite of EFB apps they are likely to be using.”

Hacking 102
article thumbnail

Weekly Update 93

Troy Hunt

I talk a lot about that in this week's update, as well as the short tutorial series I released on how HTTPS is easy. I'm really happy to see people chiming in on the discussion and talking about how they've already used it to move their site to HTTPS and I hope we see a lot more of that in the future too. HTTPS Is Easy! (I

Passwords 115
article thumbnail

Sending Spammers to Password Purgatory with Microsoft Power Automate and Cloudflare Workers KV

Troy Hunt

Until now because finally, it's live, working and devilishly beautiful 😈 Step 1: Receive Spam This is the easy bit - I didn't have to do anything for this step! This made adding HTTPS to any website easy (and free), added heaps of really neat WAF functionality and empowered us to do cool things with caching.

Passwords 363