HTTPS protects the connection you are using
TLS protects traffic when the browser is already using HTTPS. The remaining question is what happens when a user or link begins with HTTP.
HSTS adds a browser instruction
The Strict-Transport-Security header tells compatible browsers that the site should be accessed using HTTPS for a defined period. Optional directives can extend that expectation to subdomains.
Configuration matters
A short max-age, missing coverage for subdomains or deploying HSTS before every required hostname supports HTTPS can all affect the result. HSTS should be introduced deliberately.
Observe shows the browser-facing evidence
Scantide Observe can show whether the current HTTPS response presents HSTS and lets the finding be reviewed beside other browser-facing protections.
Practical depth: examples, failure modes and what to verify
Source note: current Scantide material describes the present platform. Older JufCorp/Red Cloud material is retained as field experience and historical context. Old product names, versions and configuration examples are not presented as current requirements.
Current Scantide detail
Current Scantide source: Website Tracker and Network Beacon DetectionScantide Observe is a browser-based passive evaluator that explains cookies, response headers, scripts, frames, forms, network beacons and other page-visible evidence while you browse.
Current Scantide source: Browser Security Extension for Website AnalysisScantide Observe is a browser security extension for reviewing cookies, headers, scripts, frames, forms and network behavior while visiting a page.
Current Scantide source: Scantide Observe – Website Security and Privacy Analysis in the BrowserScantide Observe provides passive browser-visible analysis of cookies, headers, scripts, iframes, forms and network activity with practical security and privacy context.
Field experience from the archive
Historical source · JufCorp: Securing your server environment - Part III - Operating systemsWhatever you'll be using your server for. have a look at any information that it "bleeds". This could for instance be headers telling any attacker exactly what version of software you're running. If possible, try to hide such information. There's no need for it to be visible and help a hacker find a way in. Simple checks using telnet to the ports your services might reveal some interesting information . Sadly, it's not possible to remove all headers etc but you should give it a go and remove as many as possible While on the subject, use SSL-certificates for any service where possible. Also make sure to set it up correctly (disable weak ciphers, enable HSTS, set correct HTTP headers, set TLS correctly etc ) . Have a look at Letsencrypt for instance for SSL certificates. It's free, supported by basically everyone and it'll probably get the job done for you . All you have to remember is to check that your certificates are renewed every three months.
Historical source · JufCorp: Using HTTP redirects for mitigating vulnerability scans and bruteforce attacksThe redirect method will only protect your server on the http/s level. f you also have other services runnning such as FTP,RDP etc they won't be protected by a simple redirect on http/s only. There's other ways to accoomplish that and I'm happy to help you out. Just drop me an email or get in contact through the form to the right or below.
Practical review checklist
- Scantide Observe is a browser-based passive evaluator that explains cookies, response headers, scripts, frames, forms, network beacons and other page-visible evidence while you browse.
- Scantide Observe is a browser security extension for reviewing cookies, headers, scripts, frames, forms and network behavior while visiting a page.
- Scantide Observe provides passive browser-visible analysis of cookies, headers, scripts, iframes, forms and network activity with practical security and privacy context.
- The redirect method will only protect your server on the http/s level.