Analysis of the Alexa Top 1M sites
blog.mozilla.org
blog.mozilla.org
Within the Alexa Top 1MM I discovered about ~1000 sites that had turned SAMEORIGIN policy off with their CORS configs [https://ejj.io/cost-of-security-headers/] (including Atlassian/Bitbucket, Zulily, and several other big ones).
I asked Scott Helme to add looking for these problematic configs to securityheaders.io but didn't have any luck. I would love some help getting traction on this issue. CORS is fundamentally ... not good and people will keep getting it wrong unless people do something.
The radio brands have streams that pass through Akamai into html and other sdk players that remove CORS protections, sometimes as the only way they function.
Can you list a few good resources for dealing with these situations, or point a guy in the right direction?
Feel free to email me at evan at segment dot com
So, it's not surprising that the features that have gotten the most adoption (like HTTPS itself) are those that show up visibly in browsers, get direct publicity, or unlock access to other things. Features like CSP, while quite useful, don't make the news when you adopt them, and don't unlock any key functionality.
E.g, to identify sites with CSP: https://discuss.httparchive.org/t/which-sites-have-content-s....
You can access raw HAR captures, as well as pre-aggregated stats via BigQuery.
Ideally there would be a way to get async loading css without onload. Is putting the style tag just before </body> acceptable? It's not valid html if I remember correctly.