list more web service / site security features
This commit is contained in:
parent
7a3a5b3f57
commit
35f926e00e
@ -210,7 +210,12 @@
|
||||
<li>Authenticated encryption for all of our services</li>
|
||||
<li>Strong cipher configurations for all of our services (SSH, TLS, etc.) with
|
||||
only modern AEAD ciphers providing forward secrecy</li>
|
||||
<li>Our web services use OCSP stapling with Must-Staple</li>
|
||||
<li>Our web services use robust OCSP stapling with Must-Staple</li>
|
||||
<li>Our web sites do not include any third party content and entirely forbid
|
||||
it via strict Content Security Policy rules</li>
|
||||
<li>Our web sites disable referrer headers to maximize privacy</li>
|
||||
<li>Our web sites fully enable cross origin isolation and disable embedding in
|
||||
other content</li>
|
||||
<li>DNSSEC implemented for all of our domains</li>
|
||||
<li>DNS Certification Authority Authorization (CAA) records for all of our
|
||||
domains permitting only Let's Encrypt to issue certificates with fully
|
||||
|
Loading…
x
Reference in New Issue
Block a user