49 articles

Creating Secure Password Resets With JSON Web Tokens

The iOS 10.3 Security Alert Is Killing App Store Downloads: Here’s How To Fix It

How To Secure Your Web App With HTTP Headers

How To Issue A New SSL Certificate With An Old SSL Key

Be Afraid Of HTTP Public Key Pinning (HPKP)

Between October 21st and 25th, Smashing Magazine became completely unavailable for a majority of visitors. Visiting Smashing Magazine would give most returning visitors with a modern browser a security warning message like this:

Some people would get a slightly different screen because of Smashing Magazine’s Service Worker kicking in, and showing a placeholder “You’re Offline” message, but the underlying cause was the same: HTTP Public Key Pinning.

