Expect-CT security header for whonix.org

Removed report-uri=“https://whonix.report-uri.com/r/d/ct/enforce”.

Hardenize: Comprehensive web site configuration test

Now showing:

report-uri x

And the x is orange, not a green arrow indicating a non-perfection.

Reporting to a third party such as report-uri.com can be a privacy issue as mentioned in "whonix.report-uri.com".

Options:

  • A) Expect-CT violation reporitng reporting to third party report-uri.com (old option)
  • B) Expect-CT without violation reporting (current option)
  • C) Expect-CT self-hosted reporting (Theoretical option. Open Source software might not exist. Reporting potential TLS issues to source of TLS issues might be conceptually flawed.)
1 Like