Monitoring Single-Page Apps: When 200 OK Means Nothing
SPAs return 200 with an empty shell even when a JavaScript error blanks the page. Why classic uptime checks miss SPA failures, and what catches them.
The .dev TLD Is Here, and It's HTTPS-Only by Design
Google's .dev domains open to the public this month, and the whole TLD is HSTS-preloaded. What preloading means, and how to launch HTTPS-only from day one.
GitHub's Day-Long Outage: Choosing Consistency Over Availability
GitHub spent about a day degraded this weekend and chose data integrity over a fast recovery. What that trade-off means, and what to check in your own pipeline.
TLS 1.3 Is Final: What RFC 8446 Changes and What to Do About It
TLS 1.3 is final as RFC 8446, after four years and 28 drafts. What changed, what was removed, and how to check what your servers negotiate.
Chrome 68 Is Here: Every HTTP Page Now Says “Not Secure”
Chrome 68 now labels every HTTP page Not Secure. A migration checklist covering free certificates, redirects, mixed content, HSTS and what comes after.
PCI's June 30 Deadline: Turning Off TLS 1.0 Without Locking Out Customers
PCI DSS requires SSL and early TLS to be gone from payment environments by June 30. How to check what you negotiate, change it safely, and spot who it breaks.
GDPR Lands in Three Days: A Practical Checklist for Website Operators
GDPR takes effect May 25. A practical, non-lawyer guide for site operators covering IP addresses, cookie consent, vendor inventories and the 72-hour breach clock.
Certificate Lifetimes Just Got Cut to 825 Days, and the Trend Points Shorter
Newly issued TLS certificates are now capped at 825 days. Why the industry keeps cutting lifetimes, and why calendar reminders are no longer enough.
1.35 Terabits Per Second: What the GitHub DDoS Teaches Everyone Else
How a 1.35 Tbps memcached amplification attack knocked GitHub offline for about ten minutes, and what the record DDoS teaches every team about preparation.
Meltdown and Spectre: Why Your Site May Get Slower Without a Single Deploy
Meltdown and Spectre patches carry a real performance cost. Why your site may get slower with no code change, and why to baseline response times now.
Chrome Is Distrusting Symantec Certificates: Your Replacement Timeline
Chrome plans to stop trusting certificates from Symantec's old CA infrastructure in two steps during 2018. How to tell if you're affected and when to act.
Chrome 62 Marks Your Forms “Not Secure”: Time to Finish the HTTPS Migration
Chrome 62 flags any HTTP page with a text input as Not Secure, search boxes included. What changed, who's affected, and a practical migration checklist.
Browse by topic
Monitor your site — free
Uptime, SSL, DNS, security-header grades and SPF/DKIM/DMARC — one dashboard, one bill. The free tier includes the security layer and allows commercial use.