Profile avatar
scotthelme.bsky.social
Hi, I'm Scott Helme, a Security Researcher, Entrepreneur and International Speaker. I'm the creator of Report URI and Security Headers, and I deliver world renowned training on Hacking and Encryption. https://scotthelme.co.uk
18 posts 2,338 followers 18 following
Regular Contributor

This is pretty nuts, we've been having issues with our @fastmail.com emails where images aren't working... They're suggesting rate limits at @cloudflare.social are the issue, but how much sense does that make? Either way, Fastmail recommendation is to stop using their app and web interface?!

We've made a few more improvements to report-uri.com over the last week! scotthelme.co.uk/stronger-tha...

New training dates! Practical TLS and PKI Training, 6-9 May 2025. Grab your Early Bird ticket now! From @ivanristic.com and taught by @scotthelme.bsky.social www.feistyduck.com/training/pra...

Four weeks until Practical TLS and PKI Training - February. Join @scotthelme.bsky.social for four half-days of work and fun! Learn how to deploy secure servers and encrypted web applications and understand theory and practice of Internet PKI. From @ivanristic.com www.feistyduck.com/training/pra...

In 2025, Let’s Encrypt are going to drop support for OCSP revocation checking in their certificates. This shouldn't cause any problems at all, but I have a funny feeling that it will... scotthelme.co.uk/lets-encrypt...

I’m live with @scotthelme.bsky.social from an *epic* cabin in the Norwegian mountains! www.youtube.com/live/LpUpq7V...

That pesky XSS has managed to get itself back to being the #1 threat?! scotthelme.co.uk/xss-ranked-1...

Last weekend, we headed to Whittlebury Hall at the legendary Silverstone Circuit for the Caterham Motorsport Awards. After a tough season, and fighting to the very end, I landed myself P2 in the championship and a pretty sizeable piece of silverware! 🥈🏆🏁🏎️🔥💨 Congrats to Paul on his well deserved P1!

The results are in for our 2024 Penetration Test, and things are looking good! 😎 scotthelme.co.uk/report-uri-p...

Upgrading my G4 Doorbell Pro to the PoE version, which requires a chunky cavity behind it. I didn’t fancy chiseling into our wall, so I designed and printed a spacer plate that mounts with no modifications! All you need is the longer screws that come in the box 😎 www.thingiverse.com/thing:6856105

🚨 24 hour warning! 🚨 Join @troyhunt.bsky.social and myself as we talk PCI DSS compliance, and how to avoid getting pwned by JavaScript! Register for this free webinar: report-uri.com/webinar/pci_...

Exactly 9 years ago today, I committed the first line of code to the report-uri.com git repository! So much has changed since then, and yet, much remains the same! Here's to one more year to hit that milestone of being a decade old! 💪

Over the last 24 hours, report-uri.com has processed more than 1,000,000,000 pieces of telemetry! This gives us a unique view of JavaScript behaviour across the Web, as observed by over 15,000,000 unique browsers around the World. Talk about Threat Intelligence capabilities!

Join me, with world renowned cybersecurity expert @troyhunt.bsky.social, founder of haveibeenpwned.com, for this live webinar! We're going to give you a 'no nonsense' take on the new PCI DSS v4.0.1 requirements, and how to meet them! report-uri.com/webinar/pci_...

I've updated my blog post to reflect the updated proposal, which has significantly extended the timeline for implementation. We will now see no change until March 2026, and the final change has been pushed all the way back to March 2028. scotthelme.co.uk/are-shorter-...

We continue to improve our features with a focus on making it easier for customers to comply with the new PCI DSS v4.0 requirements! For requirement 6.4.3, you can now store your written justification for each script with us, and, produce a PCI DSS Inventory Report. report-uri.com

This is so amazing, I can't believe how far this little idea for a project has come!! 💪 https://scotthelme.co.uk/celebrating-250-000-000-scans-on-security-headers/

Certificate lifetimes have been reduced drastically over the years, from 60 months, to 39 months, 825 days, 398 day, and next, 90 days?.. Let's take a look at what our next step for certificates lifetimes might be! https://scotthelme.co.uk/cryptographic-agility-part-1-server-certificates/