Observatory by Mozilla – automated website security testing tool
observatory.mozilla.org
Observatory by Mozilla – automated website security testing tool
1–10 of 12 posts
Re: Observatory by Mozilla – automated website security testing tool
#2Re: Observatory by Mozilla – automated website security testing tool
#3Re: Observatory by Mozilla – automated website security testing tool
#4I find it interesting how the first website ever, being info.cern.ch, fails 6 of the 10 tests, getting a 0/100.
Re: Observatory by Mozilla – automated website security testing tool
#5Re: Observatory by Mozilla – automated website security testing tool
#6I find it interesting how the first website ever, being info.cern.ch, fails 6 of the 10 tests, getting a 0/100.
It also has an invalid website certificate. Kind of a shame that it's so neglected, but it's a pretty good example of what happens to sites when they're allowed to sit for too long.
Re: Observatory by Mozilla – automated website security testing tool
#7Earlier quoted context omitted.
It also has an invalid website certificate. Kind of a shame that it's so neglected, but it's a pretty good example of what happens to sites when they're allowed to sit for too long.
I was under the impression it was recently updated for the 25th anniversary. However, I can understand not adding "security" in the name of preservation. Real shame.
Re: Observatory by Mozilla – automated website security testing tool
#8Microsoft and Google both score a "D", Mozilla itself scores a "D-", Apple and Amazon both score an "F"
We're working really hard on getting mozilla.org to the point where it also gets an A+.
Re: Observatory by Mozilla – automated website security testing tool
#9Re: Observatory by Mozilla – automated website security testing tool
#10I find it interesting (and a bit disappointing) that while github.com gets an A, a static page I host on github pages received an F. Would be great if Github would help pages hosted there be more secure by default.
Some of these things, such as subresource integrity, will be down to you and what you do with the code. Many of these tests have very little baring on how 'secure' a static page is.