anonym 22 Posted ... Hello, I think Air should have HSTS (HTTPS Strict Transport Security) enabled on your website for even more security.See this article from EFF for more information. Best regards, anonym Quote Share this post Link to post
Staff 9972 Posted ... Hello! Thanks. You can't load airvpn.org pages in HTTP. HTTPS is forced since years ago. Kind regards Quote Share this post Link to post
Strongduck 1 Posted ... HSTS tells the Browser that the website shouldn't be visited without TLS under any circumstances. Therefore a MITM Attack without a valid certificate should be much harder. Quote Share this post Link to post
Staff 9972 Posted ... Hello, I think Air should have HSTS (HTTPS Strict Transport Security) enabled on your website for even more security.See this article from EFF for more information. Best regards, anonym Hello! Yes you're right, HSTS is not enabled, we have put it in the things to do very soon. Kind regards Quote Share this post Link to post
Staff 9972 Posted ... Hello, I think Air should have HSTS (HTTPS Strict Transport Security) enabled on your website for even more security.See this article from EFF for more information. Best regards, anonym Hello! Implemented. https://www.ssllabs.com/ssltest/analyze.html?d=airvpn.org Kind regards Quote Share this post Link to post
anonym 22 Posted ... Thanks Staff! The HSTS is much appreciated! Sincerely, anonym Quote Share this post Link to post
iwih2gk 93 Posted ... Hello, I think Air should have HSTS (HTTPS Strict Transport Security) enabled on your website for even more security.See this article from EFF for more information. Best regards, anonymHello! Implemented. https://www.ssllabs.com/ssltest/analyze.html?d=airvpn.org Kind regards Response: After this change your report card from that site jumped from an A to an A+. That is their assigned grade and not my opinion on the matter. [smile] Quote Share this post Link to post