frontpage.
newsnewestaskshowjobs

Open Source @Github

fp.

Open in hackernews

Security headers on 4,688 small-business websites: 49.7% met none of 7 criteria

https://rackcrunch.com/security-headers-2026
15•terrybyte•1h ago

Comments

n4pw01f•46m ago
Nice work! You gave me something to fix!!
tumdum_•29m ago
Sadly non of it was written by a human being.
rackcrunch•8m ago
Thanks, glad it helped!
aetherspawn•29m ago
It’s ridiculous that the answer to a secure web is for everyone to sprinkle the magic salt and not something on the browser side
alserio•16m ago
we'd need an epoch like reset to good defaults
aetherspawn•5m ago
For important issues like security - just break the web, it will adjust.
rackcrunch•7m ago
Referrer-Policy shows it can work. When the header is missing, browsers fall back to strict-origin-when-cross-origin. 86.6% of the sites we scanned don't send it, and we didn't count that as a failure for that reason. The other headers don't have a safe default like that yet.
GaProgMan•23m ago
And if any of the websites use .NET, they can get almost all of the recommended security headers in one line by using a NuGet package I created: https://gaprogman.github.io/OwaspHeaders.Core/
stargrazer•11m ago
So.. you've written up what you checked, and what didn't match what ever criteria you had.

But.. what does it mean? Why enforce certain headers? Why enforce certain options? There is a section which kinda looks at this, but not really.

You have a bunch of links at the end for resources, but why not just provide the rationale for each rule or option inclusion in the article as well? What does each prevent or allow and why?

fitsumbelay•9m ago
for static sites on a VPS it's fair to expect the host to provision these, yes?

F-Droid 2.0

https://f-droid.org/2026/09/24/f-droid-2.0-a-new-chapter-for-android-freedom.html
780•daveoc64•6h ago•216 comments

Show HN: Make cursed fonts like Times New Bastard

https://bastardica.mitpit.com
331•MitPitt•23h ago•49 comments

Show HN: Whiteboard (YC W26) – An open-source IDE for thoughtful software design

https://github.com/devdotfast/whiteboard
149•sidharthkmenon•4h ago•61 comments

Show HN: Koi.rest – watch some fish and regain your balance

https://koi.rest
19•hxii•33m ago•1 comments

Opus 5.5 is good at explainer videos

https://launchvideo.io
68•iacguy•1h ago•44 comments

Why is the liver so weirdly regenerative?

https://dynomight.substack.com/p/liver
158•jbotz•5h ago•112 comments

Rails World 2026 Opening Keynote [video]

https://www.youtube.com/watch?v=vDjW_dRyKXY
178•an0malous•1d ago•190 comments

Fearless SIMD v1.0

https://linebender.org/blog/fearless-simd-1-0/
132•verdagon•2d ago•22 comments

My weird new hobby: Wandering around Tokyo on Google Maps

https://ahmedhossamdev.com/writing/my-weird-new-hobby-wandering-around-tokyo/
158•ahmedhossamdev•2d ago•68 comments

California is chasing wealth that has feet

https://blog.landeconomics.org/p/california-is-chasing-wealth-that
18•idbnstra•1h ago•26 comments

Using LLMs to trace alchemical knowledge and decode 17th century letters

https://resobscura.substack.com/p/ai-labs-need-to-start-funding-historical
40•benbreen•2h ago•8 comments

Sourcehut account takeover via build logs (XSS in ansi2html)

https://blog.arusekk.pl/posts/srht-account-takeover/
42•arusekk•2h ago•3 comments

Stable (YC W20) Is Hiring Product Engineers

https://www.usestable.com/careers/product-engineer
1•collinpham•3h ago

The Board Game of the Alpha Nerds (2014)

https://grantland.com/features/diplomacy-the-board-game-of-the-alpha-nerds/
19•neonate•1h ago•14 comments

2DWillNeverDie

https://2dwillneverdie.com/
31•surprisetalk•2d ago•2 comments

Book review: Is parallel programming hard, and, if so, what can you do about it?

https://ahelwer.ca/post/2026-09-21-concurrency-textbook/
69•ahelwer•3d ago•17 comments

Google’s Project Suncatcher to put ML infrastructure in space

https://blog.google/innovation-and-ai/models-and-research/google-research/google-project-suncatch...
72•xnx•8h ago•124 comments

Toyota is taking the Corolla electric

https://electrek.co/2026/09/23/toyota-best-selling-corolla-electric/
138•cisc•23h ago•192 comments

The forgotten battle of East Lansing

https://eastlansinginfo.news/the-forgotten-battle-of-east-lansing/
72•rmason•3d ago•10 comments

Two-tier encryption in the UK

https://macanorak.com/two-tier-encryption-in-the-uk/
346•ReturnoftheHack•11h ago•352 comments

Forging 1024-bit RSA signatures in nearly SNFS time [pdf]

https://eprint.iacr.org/2026/2131.pdf
38•int0x29•7h ago•6 comments

Geothermal heat map of US hot springs

https://www.soakingsprings.com/hot-springs/geothermal-map
64•armenarmen•1d ago•26 comments

International observers to investigate Swedish election fraud

https://www.tv4.se/artikel/37VDHaUBmbgXCIRAP1bR8f/internationell-valobservatoer-ska-foelja-upp-mi...
6•try-working•1h ago•1 comments

Tutoring company tells parents to save their money and 'use AI instead'

https://www.afr.com/policy/health-and-education/tutoring-company-tell-parents-to-save-their-money...
61•theanonymousone•6h ago•78 comments

Show HN: AgentRun: DSL to turn agents into workflows

https://github.com/Parcha-ai/agentrun
37•miguelrios•1d ago•4 comments

Early rogue AI agent activity and attempts to hack found on urlquery.net

https://transluce.org/agent-activity
223•snikolaev•16h ago•200 comments

WaveDigger: Dig into wireless signals to discover their physical locations

https://github.com/christianrowlands/wavedigger
78•882542F3884314B•1d ago•12 comments

August 27 TCRF DDoS Attack Postmortem

https://blog.xkeeper.net/the-cutting-room-floor/tcrf-2026-ddos-postmortem/
14•panic•2h ago•5 comments

Show HN: Treepeat – Code similarity detection using Tree-sitter

https://github.com/dsummersl/treepeat
40•91awebsi•2d ago•2 comments

Web-based IBM 1620 emulator and IPL-V from 1963

https://github.com/pkimpel/retro-1620
46•abrax3141•1d ago•12 comments