Remove still-why-no-https
article thumbnail

Still Why No HTTPS?

Troy Hunt

Back in July last year, Scott Helme and I shipped a little pet project that tracked the world's largest websites not implementing HTTPS by default. We called it Why No HTTPS? and I then roll the HTTP sites and HTTPS sites list into the Why No HTTPS? In that regard, it's quite simple. Read the post?

Firewall 168
article thumbnail

Why No HTTPS? The 2021 Version

Troy Hunt

More than 3 years ago now, Scott Helme and I launched a little project called Why No HTTPS? The top million is defined by Tranco and Scott uses it to produce 2 other lists which drive this little project: The top sites that redirect to HTTPS The top sites that don't redirect to HTTPS These lists don't add up to 1 million.

VPN 359
Insiders

Sign Up for our Newsletter

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

article thumbnail

Weekly Update 170

Troy Hunt

Plus, there's an all new blog post on the long-overdue update to Scott Helme's and my little Why no HTTPS? References Forbrukerrådet does some excellent work identifying risks to consumers (link to their findings from a couple of year ago around kids tracking watches) Still why no HTTPS?

Risk 138
article thumbnail

Weekly Update 256

Troy Hunt

still a heap of sites out there not doing secure connections right) Sponsored by: Varonis. Reduce your SaaS blast radius with data-centric security for AWS, G Drive, Box, Salesforce, Slack and more.

article thumbnail

HSTS From Top to Bottom or GTFO

Troy Hunt

About 80% of all web pages are loaded over an HTTPS connection , browsers are increasingly naggy when anything isn't HTTPS and it's never been cheaper nor easier to HTTPS all your things. Would I then have entered my credentials on the resulting page, even if still served insecurely?

Passwords 218
article thumbnail

Weekly Update 169

Troy Hunt

References Why No HTTPS? is getting a complete update (new data, new ranking criteria, still not enough HTTPS!) I'm going to leave that intro here, push this week's update then do it all again (hopefully also on time!) a week from now. Go home GoGetSSL, you're ad is drunk!

DNS 143
article thumbnail

How I Got Pwned by My Cloud Costs

Troy Hunt

I have been, and still remain, a massive proponent of "the cloud" I built Have I Been Pwned (HIBP) as a cloud-first service that took advantage of modern cloud paradigms such as Azure Table Storage to massively drive down costs at crazy levels of performance I never could have achieved before. But this is a storage account - why?

Passwords 363