Skip to main content

The CompleteStatus Blog

Monitoring & security, explained

Practical, no-fluff guides on uptime and security monitoring — fixing security headers, email authentication, SSL certificates, and consolidating your monitoring stack.

RSS feed
security breaches

The Equifax Breach: Anatomy of an Unpatched Vulnerability

Equifax lost data on roughly 143 million people through a Struts flaw patched two months before the attack began. Lessons on inventory, patch SLAs and detection.

6 min read
dns ssl

CAA Records Explained: Control Which CAs Can Issue Your Certificates

From September 8, every certificate authority must check CAA records before issuing. What CAA is, the syntax, and how to add it without breaking anything.

5 min read
security ransomware

WannaCry: The Patch Existed for Two Months. Why Wasn't It Installed?

WannaCry is spreading through networks using a flaw Microsoft patched in March. What the worm teaches about patch cadence, EOL systems and tested backups.

5 min read
aws outages

The S3 Outage: Why Your Status Page Can't Live on Your Own Infrastructure

Amazon's four-hour S3 outage broke a large part of the web, and AWS's own dashboard couldn't turn red. Why status pages need independent infrastructure.

6 min read
security cloudflare

Cloudbleed: What a Leaking CDN Teaches About Shared Infrastructure

Cloudflare's edge leaked memory from unrelated sites into served pages for months. What Cloudbleed teaches about shared infrastructure and secrets.

6 min read
backups databases

The GitLab.com Database Incident: A Backup You Haven't Restored Is Just a Hope

Last week GitLab.com lost hours of production data and found its backups weren't working. What happened, and how to check your own before you need them.

7 min read
http2 performance

HTTP/2 Is Ready: What It Actually Means for Your Site

HTTP/2 is now practical to deploy. What multiplexing and header compression change, how to enable it on nginx, and which old habits to unwind.

5 min read
ssl sha-1

SHA-1 Certificates Stop Working in January: Check Yours Now

Chrome and Firefox plan to stop trusting SHA-1 certificates early in 2017. How to find any that are still in your chains, and what replacing them involves.

6 min read
dns ddos

The Dyn Attack: DNS Is the Single Point of Failure Everyone Forgets

Last Friday a botnet of cameras and DVRs knocked out Dyn's DNS, and Twitter, Reddit and Spotify with it. Lessons on DNS redundancy, TTLs and monitoring.

5 min read
outages disaster-recovery

Delta and Southwest: When the Backup Data Center Isn't a Backup

Two airlines, two data center failures, thousands of cancelled flights in a month. What they suggest about failover plans that exist mostly on paper.

7 min read
monitoring uptime

Website Monitoring vs. Server Monitoring: Why Green Dashboards Lie

Nagios says CPU and disk are fine, yet a visitor overseas sees a timeout. Why external website checks catch what server agents cannot.

5 min read
ssl lets-encrypt

Let's Encrypt Is Out of Beta: Free HTTPS for Everyone, and a New Way to Fail

Let's Encrypt has left beta after issuing over a million free certificates. How ACME works, a basic nginx setup, and the silent renewal failure to watch for.

5 min read

Browse by topic

Monitor your site — free

Uptime, SSL, DNS, security-header grades and SPF/DKIM/DMARC — one dashboard, one bill. The free tier includes the security layer and allows commercial use.