Hacker Newsnew | past | comments | ask | show | jobs | submitlogin
HTTP Observatory: analyze your website and review available methods to secure it (github.com/mozilla)
128 points by based2 on Aug 27, 2016 | hide | past | favorite | 16 comments


Their description doesn't really match what they do:

"Observatory by Mozilla is a project designed to help developers, system administrators, and security professionals configure their sites safely and securely. "

All they check is if you have a few security headers and consider that "secure".

There is a LOT more to website security than adding a few extra headers and HTTPS to your site. Even if you get an A, it doesn't mean anything.

To give an example, Google gets a D, CloudFlare a D, Youtube a C+, etc..


> Google gets a D, CloudFlare a D, Youtube a C+

That is probably due to the non-trivial number of clients which don't support modern stuff (old browser, etc.).


I don't see a problem. They don't claim to be a one-stop integrated security scanner for all your website needs. I'd be happy if they explicitly included something like a link to OWASP with "get more detailed info here". But I don't think they're misrepresenting the service.


it seems similar to securityheaders.io


Direct link to the live Observatory: https://observatory.mozilla.org/

Example run on addons.mozilla.org: https://observatory.mozilla.org/analyze.html?host=addons.moz...

The Observatory measures site's compliance with the Web Security guidelines [1] and the Server Side TLS guidelines [2]. It's primarily meant as a helper for website developers and operators.

[1] https://wiki.mozilla.org/Security/Guidelines/Web_Security

[2] https://wiki.mozilla.org/Security/Server_Side_TLS

(disclaimer: I work on security at Mozilla)


Maybe it should be called it Https observatory?

I run http only site, I installed everything from scratch and minimized all attack surfaces. I got F because I'm lacking https stuff.

But maybe I'm missing something. If you don't deal with user logins and no sessions. Do I need to get https?

Or is this site just assuming things?


You need https to guarantee data in transit is not being modified between your server and web clients. ISPs, for instance, have a bad tendency to inject tracking cookies in http traffic.


Ahhh. Okay. Thanks.


It's 2016. There's just no excuse anymore not to do TLS.


Yep, agree 100% very short sighted view of security. Their grades doesn't mean anything, other than confuse people thinking they are secure.


SecurityHeaders.io has been doing this well for years, and without pretending to be more than header analysis.


It actually includes a summary result for https://securityheaders.io on the page. That site, your suggestion, says "A scotthelme.co.uk project - CC-BY-SA 4.0" so I wouldn't be surprised given the similarity in presentation if Observatory was based in some way on SecurityHeaders.io.




Gives Google a D.

https://observatory.mozilla.org/analyze.html?host=google.com

(Would take this rating with a grain of salt.)





Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: