HTTP Strict Transport Security — Why you need it, five common mistakes and how to fix them.THE POWER OF HTTPSATTACKING THE ENTRY POINTONE HEADER TO BIND THEM ALLCOMMON MISTAKESA Strict-Transport-Security header is served via HTTPmax-age is set too lowmax-age is set to 0includeSubDomainspreload is not used (correctly)CONCLUSION
Google กำลังจะเปลี่ยนมาใช้ HSTS สำหรับการเข้ารหัสของ Domain
HTTP Strict Transport Security (HSTS), English versionHTTPs Strict Transport Security The problem with the real worldURL to HTMLIntegrity protection for third-party JavaScriptDEF CON 27 - BEN SADEGHIPOUR - owning the clout through ssrf and pdf generatorsIntegrity protection for third-party JavaScriptTop Ten Web Hacking Techniques (2010)Same Origin Policy WeaknessesBrightonSEO Sep 2015 - HTTPS | Mark Thomas The internet for SEOs by Roxana StinguSame Origin Policy WeaknessesMitigating CSRF with two lines of codesWordPress Security:Defend yourself against digital invadersClient sidesec 2013-introSEO report for phone-sex-chat.comJavaScript Security: Mastering Cross Domain Communications in complex JS appl...Web Browsers And Other Mistakes.htaccess for SEOs - A presentation by Roxana StinguClient sidesec 2013 - non jsChrome Dev Summit 2020 Extended: Improve Your Web Authentication SecurityHTTP Strict Transport Security (HSTS), English version