-
Notifications
You must be signed in to change notification settings - Fork 19
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Inconsistency on HSTS detection between the docker, the repo and the website #59
Comments
Hello here! I guess your I got the same |
Hello again ! Thanks for pointing out cryptcheck.fr. I still find problems in the HSTS detection, it's always there when using this repo code, while on cryptcheck.fr it's not. An example with the nsa.gov website, getting "A+" on cryptcheck.fr and "E" on the repo for no HSTS detection. Thank you very much ! |
I don't understand, currently https://cryptcheck.fr/https/nsa.gov display HSTS and docker too
(And I discover it is incorrectly reported in both case, I must HSTS check on |
Okay my bad, the docker seems to give the same answers as cryptcheck.fr indeed. I was concerned about the bin/cryptcheck from the repo. When I do "./cryptcheck https nsa.gov" I get "E" for no HSTS.
Thanks ! :) |
Hello,
I find inconsistencies while using cryptcheck, depending on if you're using it from this repo, from the docker or on the website.
When I try for example the french secret services website at dgse.gouv.fr I get :
The docker is almost always giving very bad reviews while the site seems pretty accurate.
Furthemore I think by using the repo's app we can't detect HSTS and thus ends up with poor grades for every sites.
Is there something going on with the parameters or something else I didn't see ?
Any help is appreciated ! Thank you !
The text was updated successfully, but these errors were encountered: