Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Their description doesn't really match what they do:

"Observatory by Mozilla is a project designed to help developers, system administrators, and security professionals configure their sites safely and securely. "

All they check is if you have a few security headers and consider that "secure".

There is a LOT more to website security than adding a few extra headers and HTTPS to your site. Even if you get an A, it doesn't mean anything.

To give an example, Google gets a D, CloudFlare a D, Youtube a C+, etc..



> Google gets a D, CloudFlare a D, Youtube a C+

That is probably due to the non-trivial number of clients which don't support modern stuff (old browser, etc.).


I don't see a problem. They don't claim to be a one-stop integrated security scanner for all your website needs. I'd be happy if they explicitly included something like a link to OWASP with "get more detailed info here". But I don't think they're misrepresenting the service.


it seems similar to securityheaders.io




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: