<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Security-Headers on Zach Grace</title><link>https://zachgrace.com/tags/security-headers/</link><description>Recent content in Security-Headers on Zach Grace</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Thu, 13 Oct 2016 00:00:00 +0000</lastBuildDate><atom:link href="https://zachgrace.com/tags/security-headers/index.xml" rel="self" type="application/rss+xml"/><item><title>Acing Your Security Headers</title><link>https://zachgrace.com/posts/2016-10-13-security-headers/</link><pubDate>Thu, 13 Oct 2016 00:00:00 +0000</pubDate><guid>https://zachgrace.com/posts/2016-10-13-security-headers/</guid><description>&lt;p>Mozilla recently released a security header grading site, &lt;a href="https://observatory.mozilla.org/">https://observatory.mozilla.org/&lt;/a>. Of course I had to plug my site into the scanner and found that I got an F. Not good for a security guy.&lt;/p>
&lt;p>&lt;img src="https://zachgrace.com/assets/img/observatory_F.png" alt="Observatory F Rating" />&lt;/p>
&lt;p>According to &lt;a href="https://medium.com/mozilla-tech/promoting-security-best-practices-with-observatory-7b164a190425#.5gj02ihca">April King&lt;/a> of Mozilla, the Observatory &lt;em>&amp;ldquo;grading is set very aggressively to promote best practices in web security&amp;rdquo;&lt;/em>. And by looking at the scores, we can see that the far majority of sites fail the Observatory tests.&lt;/p></description></item></channel></rss>