From 62ce2c3a30726734f4bd9e92e0f5db27612e0d15ee0cd0eb6c106afa96bc56d4 Mon Sep 17 00:00:00 2001 From: Nicholas Johnson Date: Thu, 24 Aug 2023 00:00:00 +0000 Subject: Add tag 'computing' --- content/entry/oxen-security-fail.md | 1 + 1 file changed, 1 insertion(+) (limited to 'content/entry/oxen-security-fail.md') diff --git a/content/entry/oxen-security-fail.md b/content/entry/oxen-security-fail.md index 5ad80a0..a32abef 100644 --- a/content/entry/oxen-security-fail.md +++ b/content/entry/oxen-security-fail.md @@ -1,6 +1,7 @@ --- title: "Oxen Security Fail" date: 2021-09-28T00:00:00 +tags: ['computing'] draft: false --- Lately I've been doing research on the Oxen Privacy Tech Foundation and their various projects. On 19 September while looking at Session, I noticed getsession.org was missing the [Strict-Transport-Security header](https://securityheaders.com/?q=https%3A%2F%2Fgetsession.org&followRedirects=on). So I decided to also check the security headers for [oxen.io](https://securityheaders.com/?q=https%3A%2F%2Foxen.io&followRedirects=on), [lokinet.org](https://securityheaders.com/?q=https%3A%2F%2Flokinet.org&followRedirects=on), and [optf.ngo](https://securityheaders.com/?q=https%3A%2F%2Foptf.ngo&followRedirects=on) and what do you know, they're also missing HTTP security headers. -- cgit v1.2.3