Skip to main content

Security guides and articles

Every CompleteStatus blog post tagged Security — 34 articles, newest first.

Articles

https tls

Fixing Mixed Content Warnings — Finishing the HTTPS Migration You Started

Active vs passive mixed content, how browsers treat each, finding hardcoded http:// URLs, CSP upgrade-insecure-requests, and staying clean after migration.

6 min read
security ransomware

Kaseya VSA: When the Tool That Manages Everything Gets Hit

Ransomware pushed through Kaseya VSA over a holiday weekend reached businesses via their IT providers. What agencies and small teams should check now.

6 min read
security supply-chain

SolarWinds Orion: When the Monitoring Tool Is the Way In

A trojanized Orion update reached thousands of networks. What we know so far, and what it means for any tool that holds the keys to your infrastructure.

6 min read
cookies samesite

Chrome's SameSite Cookie Change Is Fully Live — What Silently Breaks

Chrome now treats cookies as SameSite=Lax by default, breaking cross-site POSTs, SSO and payment callbacks. What changed, what breaks, and how to fix it.

6 min read
tls ssl

TLS 1.0 and 1.1 Are Being Shut Out — Time to Check What Your Server Negotiates

Chrome, Firefox and Edge now block TLS 1.0 and 1.1. How to test what your server negotiates, enable TLS 1.2/1.3 on nginx and Apache, and handle legacy clients.

6 min read
remote-work monitoring

Your VPN Is Production Now: Monitoring the Infrastructure Remote Work Depends On

A month into working from home, the VPN, SSO and internal tools are business-critical. What to monitor, and what not to expose in a hurry.

7 min read
security cloud

The Capital One Breach: SSRF, Metadata Endpoints and Over-Privileged Roles

A week after Capital One disclosed its breach, here's what the public record says, why SSRF keeps coming up, and what to check on your own cloud servers.

7 min read
hsts https

The .dev TLD Is Here, and It's HTTPS-Only by Design

Google's .dev domains open to the public this month, and the whole TLD is HSTS-preloaded. What preloading means, and how to launch HTTPS-only from day one.

6 min read
tls security

TLS 1.3 Is Final: What RFC 8446 Changes and What to Do About It

TLS 1.3 is final as RFC 8446, after four years and 28 drafts. What changed, what was removed, and how to check what your servers negotiate.

5 min read
https chrome

Chrome 68 Is Here: Every HTTP Page Now Says “Not Secure”

Chrome 68 now labels every HTTP page Not Secure. A migration checklist covering free certificates, redirects, mixed content, HSTS and what comes after.

5 min read
tls pci

PCI's June 30 Deadline: Turning Off TLS 1.0 Without Locking Out Customers

PCI DSS requires SSL and early TLS to be gone from payment environments by June 30. How to check what you negotiate, change it safely, and spot who it breaks.

6 min read
gdpr privacy

GDPR Lands in Three Days: A Practical Checklist for Website Operators

GDPR takes effect May 25. A practical, non-lawyer guide for site operators covering IP addresses, cookie consent, vendor inventories and the 72-hour breach clock.

6 min read

More topics