HTTPS is Not Enough

Tim Perry
November 03, 2016

  Automatically switch URLs to HTTPS Content-Security-Policy: upgrade-insecure-requests

  Report switched URLs Content-Security-Policy: upgrade-insecure-requests; report-uri /report-csp;

  Report-only, for testing Content-Security-Policy-Report-Only: upgrade-insecure-requests; report-uri /report-csp;

  Free reporting platform:

  Strict-Transport-Security: max-age=31556926; includeSubDomains; preload Great example Then submit to

  50. Needs to be set on root domain ( Required on

    Serve content with HTTPS only Use upgrade-insecure-requests Use HSTS, and get preloaded Check other sites ( and complain! Let's build a secure web
  53. Serve content with HTTPS only Use upgrade-insecure-requests Use HSTS, and

    get preloaded Check other sites ( and complain! Let’s build a secure web @pimterry
