πŸŽ—οΈ

Security Headers Are Overrated

Tags
Practice
Date
Jul 2, 2022
Why? We shouldn't have done reporting bunch of false positive unfulfilled security headers. We have to be conscious about the context and the usage of why those headers being existed.
Β 
List of the security headers:
  1. Content-Security-Policy (CSP)
  1. Strict-Transport-Security Header (HSTS)
  1. X-Content-Type-Options
  1. X-Frame-Options
  1. Referrer-Policy
  1. Access-Control-Allow-Origin
Β