Scott Helme
Security researcher; built Report URI and Security Headers, and writes about web security in practice.
Scott Helme did not write this page. What is this?
It collects the places they publish and what they have said there, each linked to the source. They have no account here. Is this you? Claim it, correct it, or ask us to remove it from ppll.
Where they publish
Blog scotthelme.co.uk His blog on web security, certificates and headers. Has a feed.
Recent
- No Hacking Required: The Manchester Airports Group Data Breach 7 Sept 2026 On 27 August 2026, Manchester Airports Group told customers that "an unauthorised third party" had stolen their data. Car park bookings, lounge bookings, Fast Track purchases for airport security and passport control, a…
- The ultimate road trip combo: Starlink Mini + UniFi Travel Router 24 Aug 2026 I recently went on an epic road trip around Europe, covering 1,645 miles (2,647 km), and we took in some amazing sights and locations. As a tech geek, I was worried about my connectivity on the trip, so before we set of…
- Introducing dbsc.dev: Does Your Browser Support DBSC? 21 Aug 2026 Every other web platform feature I've ever written about, I've been able to test in some easy way. Open DevTools, type the name of the thing, see if it's there. Device Bound Session Credentials doesn't work like that: t…
Show 12 more
- Device Bound Session Credentials lands in Chrome on macOS 11 Aug 2026 Device Bound Session Credentials (DBSC) is Chrome's answer to session cookie theft, usually by InfoStealer malware. Instead of a cookie being a bearer token that works anywhere it's pasted, DBSC binds the session to a p…
- Everything I Learned Shipping Device Bound Session Credentials 10 Aug 2026 We shipped Device Bound Session Credentials at Report URI, open-sourced the server-side implementation, and then discovered a long list of things the specification doesn't prepare you for. Some caused random logouts. On…
- Connection Allowlist: a network firewall, built into the browser 8 Jul 2026 Connection Allowlist is a new browser security mechanism that lets a document declare, up front, the exact set of destinations it's permitted to open network connections to. Anything not on the list is blocked by the br…
- Top 1 Million Analysis – June 2026: The State of Crypto 1 Jul 2026 This is part two of the ten-year anniversary Top 1 Million Analysis. Part one covered the broad state of the web — HTTPS, the security headers, cookies, email and DNS hygiene. This part is the bit I've been most excited…
- Top 1 Million Analysis – June 2026: Ten Years of Web Security 29 Jun 2026 It's been a long time since the last one of these! The previous Top 1 Million Analysis was way back in June 2022, and a lot has happened since then. But there's a much bigger reason to dust off the crawler and publish a…
- A dead CDN, a wildcard, and an attack waiting to happen: the netdna-ssl.com takeover 24 Jun 2026 Every now and then I go digging through Report URI's Threat Intelligence data feeds, looking for domains that show up in CSP reports where they really shouldn't. Last week one jumped out at me: netdna-ssl.com. If you've…
- Why No Passkeys? Naming the Top Sites That Still Don't Support Them 22 Jun 2026 Back in 2017, Troy Hunt and I built a little website called whynohttps.com. The idea was simple: take the most popular sites on the internet, check which ones still weren't redirecting visitors to HTTPS, and put the lag…
- The Instructure Canvas Breach (2026): How XSS in a Support Ticket Compromised 275 Million Students 15 Jun 2026 A single support ticket became the front door to 275 million student records. The Canvas breach shows how quickly untrusted user content can become a serious security incident when it is rendered inside privileged inter…
- Open-Sourcing dbsc-php: a Server Library for Device Bound Session Credentials in PHP 8 Jun 2026 We’ve open-sourced dbsc-php, a small PHP library that makes it easier to deploy Device Bound Session Credentials and turn stolen session cookies into something far less useful. It's MIT-licensed, pure-PHP, and available…
- DBSC Beta at Report URI 5 Jun 2026 This week, I published a blog post about Device Bound Session Credentials, a new technology that will significantly hamper the efforts of Infostealers and reduce the damage caused by stolen cookies. Today, we're announc…
- Device Bound Session Credentials: Making Stolen Cookies Useless 2 Jun 2026 A stolen session cookie can be vastly more powerful than a stolen password. The attacker doesn’t need to phish the user, bypass MFA, or defeat their passkey; they simply replay the cookie and step straight into a fully…
- Passkeys, Permissions Policy and Bug Hunting in 1Password's WebAuthn Wrapper 21 May 2026 Passkeys are the best thing to happen to web authentication in years, but a passkey ceremony is only as secure as the stack enforcing it. The browser, the relying party, the authenticator, and any extension sitting betw…
Link verified 20 Sept 2026. Recent items update automatically from the channel.
Beliefs
Korrents What they believe 6 beliefs — each backed by an exact quote.
Each is a — compiled by korrents.com, not by them: the one-line wordings are korrents', the quotes are theirs.
Recent
HTTPS is now simply how the web works, and the long tail of plain-HTTP sites shrinks every year.
HTTPS is now simply how the web works, and the long tail of plain-HTTP sites is shrinking every year.
Top 1 Million Analysis – June 2026: Ten Years of Web Security Said 29 Jun 2026
The web really is more secure than it was a decade ago.
The web really is more secure than it was a decade ago.
Top 1 Million Analysis – June 2026: Ten Years of Web Security Said 29 Jun 2026
A security header being present is not the same as it being deployed well, and most HSTS deployments are weaker than they look.
A lot of HSTS deployments are weaker than they look.
Top 1 Million Analysis – June 2026: Ten Years of Web Security Said 29 Jun 2026
Show 3 more
Content Security Policy adoption has more than doubled while nearly half of the policies still contain directives that undermine them.
So while CSP adoption has more than doubled, nearly half of all policies are in need of some TLC.
Top 1 Million Analysis – June 2026: Ten Years of Web Security Said 29 Jun 2026
Every website needs HTTPS, including a static site with no login and nothing sensitive on it.
Supporting HTTPS on your site has so much more to offer than just protecting passwords and user's sensitive data.
Still think you don't need HTTPS? Said 28 Mar 2016
Plain HTTP lets anyone on the path rewrite the page, so HTTPS is about the integrity of what readers get, not only secrecy.
When you serve your pages over HTTP, anyone along the transport layer can do basically anything they want to your pages. More and more often it's becoming increasingly common for somebody in the chain of custody to do something to your pages that you don't want them to do.
Still think you don't need HTTPS? Said 28 Mar 2016
Beliefs others hold too
Every website needs HTTPS, including a static site with no login and nothing sensitive on it. 2 hold this
Supporting HTTPS on your site has so much more to offer than just protecting passwords and user's sensitive data.
Still think you don't need HTTPS? Said 28 Mar 2016
What is a korrent?
A korrent is a belief a person has stated in their own words: one sentence stating the claim, backed by a quote and a source, kept at korrents.com.
Under a name here, the quoted block is what they actually said. The korrent beneath it is the claim those words support, in korrents' wording — tap it to see the record, its source, and who else holds it.
Nobody here wrote their own korrents. They are compiled from public statements, and a person can change their mind, which is recorded too.
Feed
As its own page →Hiding
7 September
24 August
21 August
11 August
10 August
8 July
1 July
29 June
From one piece Top 1 Million Analysis – June 2026: Ten Years of Web Security 4 beliefs · scotthelme.co.uk
-
Their words
So while CSP adoption has more than doubled, nearly half of all policies are in need of some TLC.
-
Their words
A lot of HSTS deployments are weaker than they look.
-
Their words
The web really is more secure than it was a decade ago.
+ 1 more
-
korrents.com
HTTPS is now simply how the web works, and the long tail of plain-HTTP sites shrinks every year.Their words
HTTPS is now simply how the web works, and the long tail of plain-HTTP sites is shrinking every year.
24 June
22 June
15 June
8 June
5 June
2 June
21 May
Nothing matches.
About the English under a post
Some people here publish in a language other than English. Where they do, this site shows a machine translation beneath the post, in this typeface — the site's own, not theirs.
The post itself is never changed, moved or hidden: what is set in the serif above is exactly what the person published, and it is what to quote them on. A translation can be wrong in ways that matter, especially about tone.
Only the post's own words are translated. A quoted post, a linked article and a belief on korrents.com are left in their original language.