It's been a while since I've had chance to sit down and produce a report on the security of the Top 1 Million sites, but thanks to @Venafi's support, the crawler project lives on and a brand new report is out! venafi.com/blog/crawler-r…
It takes a lot of resources to gather this data and a lot of time to analyse it all and write the report, so genuinely, it wouldn't have happened without them. There hasn't been a report for 18+ months so let's take a look at what changed! 😎
HTTPS adoption continues to surge 🔐📈
72% of sites in the Top 1M are now actively redirecting HTTP --> HTTPS 🤩
We're using more HTTPS right now than at any point in history... 😮
Redirecting to HTTPS isn't quite enough though, sites also need to use HSTS and we've seen strong growth there too! ✔
Without any doubt, credit has to be given to @letsencrypt as the largest issuing CA in the Top 1M sites by quite some margin! 💪
Almost 25% of the Top 1M sites are using a @letsencrypt certificate, 240,461 sites!
The presence of @letsencrypt is smaller in the largest sites as they are still using more traditional CAs.
@letsencrypt isn't the only big change in the CAs though, we can see a large shift towards automated or service provided certificates!
As HTTPS surges, it seems sites are choosing DV over EV when it comes to certificates. EV is now at the lowest usage levels I've recorded. 📉
My suspicions: 1. EV certs are 💰💰💰 2. EV certs are harder to automate 🔄 3. EV UI removed in the browser ❌🔒
Another very notable trend in the Top 1M sites is the use of @Cloudflare! ⛅
You can see their presence in the certificate stats above, but it really shows when you look at the server headers of sites and see they're the clear choice 🥇
I suspect this large presence of @Cloudflare is largely responsible for some other positive trends we've seen. ⛅📈🔒
For example, the new TLSv1.3 protocol has seen faster adoption than I expected since it's standardisation in 2018.
Adoption of TLSv1.3 changes the preferred cipher suites for the Top 1M sites. 🧾
The clear winner is a TLSv1.3 suite, whilst TLSv1.2 suites still hold firm in 2nd and 3rd place.
I also recall @zeeg once talking about customers on a $50/mo sub wanting custom legal terms / NDAs / security reviews etc... but I can't find the tweet. It'd take us years to recoup the cost of onboarding them.
The latest one today is "Dear Scott, we signed up to your service and now as our supplier your are required to x, y and z". Security questionnaire, supplier questionnaire, NDA, provide various compliance certs if we have them and they need our invoices in a different format 🤷♂️
I bought a phone from a large retailer here in the UK and they shipped a faulty unit. These things happen, so I return it for a refund and they got it on 6th Aug:
They had no other phones of the same spec anyway so they said they were going to refund me. By 13th Aug, still no refund.
I chased a couple more times and by 14th Sep, still no refund! They say it will now take them 3-5 days to issue a refund:
Are you using CSP on your website? You might be getting a patent infringement notice! Buckle up 😎 scotthelme.co.uk/i-turned-on-cs…
We're already working with the @EFF who will hopefully be able to support the cause here, but we need to know about other websites that have received this letter.
If you're legally and/or technically minded, perhaps you could take a look over the letter being sent out: drive.google.com/file/d/1p63IJ6…