Skip to main content

Security guides and articles

Every CompleteStatus blog post tagged Security — 34 articles, newest first.

Articles

ddos security

1.35 Terabits Per Second: What the GitHub DDoS Teaches Everyone Else

How a 1.35 Tbps memcached amplification attack knocked GitHub offline for about ten minutes, and what the record DDoS teaches every team about preparation.

5 min read
security performance

Meltdown and Spectre: Why Your Site May Get Slower Without a Single Deploy

Meltdown and Spectre patches carry a real performance cost. Why your site may get slower with no code change, and why to baseline response times now.

6 min read
ssl certificates

Chrome Is Distrusting Symantec Certificates: Your Replacement Timeline

Chrome plans to stop trusting certificates from Symantec's old CA infrastructure in two steps during 2018. How to tell if you're affected and when to act.

5 min read
https chrome

Chrome 62 Marks Your Forms “Not Secure”: Time to Finish the HTTPS Migration

Chrome 62 flags any HTTP page with a text input as Not Secure, search boxes included. What changed, who's affected, and a practical migration checklist.

5 min read
security breaches

The Equifax Breach: Anatomy of an Unpatched Vulnerability

Equifax lost data on roughly 143 million people through a Struts flaw patched two months before the attack began. Lessons on inventory, patch SLAs and detection.

6 min read
dns ssl

CAA Records Explained: Control Which CAs Can Issue Your Certificates

From September 8, every certificate authority must check CAA records before issuing. What CAA is, the syntax, and how to add it without breaking anything.

5 min read
security ransomware

WannaCry: The Patch Existed for Two Months. Why Wasn't It Installed?

WannaCry is spreading through networks using a flaw Microsoft patched in March. What the worm teaches about patch cadence, EOL systems and tested backups.

5 min read
security cloudflare

Cloudbleed: What a Leaking CDN Teaches About Shared Infrastructure

Cloudflare's edge leaked memory from unrelated sites into served pages for months. What Cloudbleed teaches about shared infrastructure and secrets.

6 min read
ssl sha-1

SHA-1 Certificates Stop Working in January: Check Yours Now

Chrome and Firefox plan to stop trusting SHA-1 certificates early in 2017. How to find any that are still in your chains, and what replacing them involves.

6 min read
https tls

Why Your Website Needs HTTPS, Even If It's a Brochure Site

Free certificates, a small Google ranking boost, HTTP/2 and ad-injecting hotspots: why every site should move to HTTPS in 2016, not just stores.

5 min read

More topics