What does upgrade-insecure-requests do that HSTS and redirects don't?
-
-
-
Cascades down to all content embedded insecurely in the page regardless of the origin it’s served from
End of conversation
New conversation -
-
-
Quickly?! It's been a known issue for years! Have I missed the sarcasm?
-
Quickly, as in properly and authoritatively made to look to be doing the wrong thing and then beginning to deal with it. That's my take.
-
That'd be fair... in 2012 when it first came about :)
-
Banks and large orgs don't take any advice from 'security researchers' until there's a following groundswell of support, followed by media coverage. Then they do. That's the difference here I think. ;) 2012, is so... 2012. :D
End of conversation
New conversation -
-
-
Perhaps you can help
@HSBC_UK as their homepage is in a similar state. What is it with banks?Thanks. Twitter will use this to make your timeline better. UndoUndo
-
-
-
This is great work by
@troyhunt to get Natwest finally fix their site for HTTPS (well they’ve made a start anyway)https://twitter.com/troyhunt/status/941403018909454336 …Thanks. Twitter will use this to make your timeline better. UndoUndo
-
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.