Hacker News new | ask | show | jobs
by deftnerd 2532 days ago
This is a good basic overview of the basic headers, but I suggest spending some time on Scott Helme's blog. He runs securityheaders.io, a free service that scans your site, and assigns it a letter grade based on what headers and configurations you've applied.

For instance, his explanation of Content Security Policy headers is much more detailed than in the OP's link.

https://scotthelme.co.uk/content-security-policy-an-introduc...

2 comments

securityheaders.io is now securityheaders.com

https://scotthelme.co.uk/security-headers-is-changing-domain...

Mozilla Observatory does the same thing. https://observatory.mozilla.org/