Skip to main content

The CompleteStatus Blog

Monitoring & security, explained

Practical, no-fluff guides on uptime and security monitoring — fixing security headers, email authentication, SSL certificates, and consolidating your monitoring stack.

RSS feed
spa javascript

Monitoring Single-Page Apps: When 200 OK Means Nothing

SPAs return 200 with an empty shell even when a JavaScript error blanks the page. Why classic uptime checks miss SPA failures, and what catches them.

5 min read
hsts https

The .dev TLD Is Here, and It's HTTPS-Only by Design

Google's .dev domains open to the public this month, and the whole TLD is HSTS-preloaded. What preloading means, and how to launch HTTPS-only from day one.

6 min read
outages github

GitHub's Day-Long Outage: Choosing Consistency Over Availability

GitHub spent about a day degraded this weekend and chose data integrity over a fast recovery. What that trade-off means, and what to check in your own pipeline.

6 min read
tls security

TLS 1.3 Is Final: What RFC 8446 Changes and What to Do About It

TLS 1.3 is final as RFC 8446, after four years and 28 drafts. What changed, what was removed, and how to check what your servers negotiate.

5 min read
https chrome

Chrome 68 Is Here: Every HTTP Page Now Says “Not Secure”

Chrome 68 now labels every HTTP page Not Secure. A migration checklist covering free certificates, redirects, mixed content, HSTS and what comes after.

5 min read
tls pci

PCI's June 30 Deadline: Turning Off TLS 1.0 Without Locking Out Customers

PCI DSS requires SSL and early TLS to be gone from payment environments by June 30. How to check what you negotiate, change it safely, and spot who it breaks.

6 min read
gdpr privacy

GDPR Lands in Three Days: A Practical Checklist for Website Operators

GDPR takes effect May 25. A practical, non-lawyer guide for site operators covering IP addresses, cookie consent, vendor inventories and the 72-hour breach clock.

6 min read
ssl tls

Certificate Lifetimes Just Got Cut to 825 Days, and the Trend Points Shorter

Newly issued TLS certificates are now capped at 825 days. Why the industry keeps cutting lifetimes, and why calendar reminders are no longer enough.

5 min read
ddos security

1.35 Terabits Per Second: What the GitHub DDoS Teaches Everyone Else

How a 1.35 Tbps memcached amplification attack knocked GitHub offline for about ten minutes, and what the record DDoS teaches every team about preparation.

5 min read
security performance

Meltdown and Spectre: Why Your Site May Get Slower Without a Single Deploy

Meltdown and Spectre patches carry a real performance cost. Why your site may get slower with no code change, and why to baseline response times now.

6 min read
ssl certificates

Chrome Is Distrusting Symantec Certificates: Your Replacement Timeline

Chrome plans to stop trusting certificates from Symantec's old CA infrastructure in two steps during 2018. How to tell if you're affected and when to act.

5 min read
https chrome

Chrome 62 Marks Your Forms “Not Secure”: Time to Finish the HTTPS Migration

Chrome 62 flags any HTTP page with a text input as Not Secure, search boxes included. What changed, who's affected, and a practical migration checklist.

5 min read

Browse by topic

Monitor your site — free

Uptime, SSL, DNS, security-header grades and SPF/DKIM/DMARC — one dashboard, one bill. The free tier includes the security layer and allows commercial use.