{"id":2985,"date":"2016-08-29T13:58:51","date_gmt":"2016-08-29T13:58:51","guid":{"rendered":"https:\/\/www.thesslstore.com\/blog\/?p=2985"},"modified":"2016-08-29T14:00:28","modified_gmt":"2016-08-29T14:00:28","slug":"mozilla-releases-observatory","status":"publish","type":"post","link":"https:\/\/www.thesslstore.com\/blog\/mozilla-releases-observatory\/","title":{"rendered":"Mozilla Releases \u201cObservatory,\u201d a Website Security Scanner"},"content":{"rendered":"<h2>The free tool checks a site\u2019s SSL configuration and more.<\/h2>\n<p><a href=\"https:\/\/twitter.com\/aprilmpls\"\"rel=\"nofollow\">April King<\/a>, a security engineer at Mozilla, has created a free tool for scanning the security configuration of websites. The tool, named Observatory, was created to help system administrators and developers assess and understand how to implement modern security standards.<\/p>\n<p>Observatory grades websites on what security technologies they implement, and how well they do it. Sites are assigned a score, from an A+ to an F, and each factor is individually broken out to explain what needs to be improved. More than a dozen security technologies are tested, including the site\u2019s SSL\/TLS configuration, HTTP headers, use of secure cookies, public key pinning (HPKP), content security policy (CSP) and more. All you have to do is enter in your site\u2019s URL and automated tests assess all of these factors and how you can improve (or implement) them.<\/p>\n<p>One of the key goals of Observatory is to educate. In a <a href=\"https:\/\/pokeinthe.io\/2016\/08\/25\/observatory-by-mozilla-a-new-tool\/\"\"rel=\"nofollow\">blog post on her personal site<\/a>, King wrote \u201cthere wasn\u2019t one place to go for site operators to learn what each of the technologies do, how to implement them, and how important they were.\u201d<\/p>\n<p>Now there is.<\/p>\n<p>Each test in Observatory includes links to Mozilla documentation and guides to help admins improve their site\u2019s configurations, and all the technical jargon is explained through tooltips.<\/p>\n<p>King was also inspired to create the tool after seeing how few websites are implementing modern security technologies: \u201cObservatory has been used to scan over 1.3 million websites so far, and 91% of them don\u2019t take advantage of modern security advances. These aren\u2019t tiny sites either; among these 1.3 million websites are some of the most popular websites in the world.\u201d<\/p>\n<p>Observatory integrates well-known third-party scanning tools such as:<\/p>\n<ul>\n<li>hsts.preload.appspot.com (A tool used to manage the HSTS preload list)<\/li>\n<li>securityheaders.io (for testing HTTP headers)<\/li>\n<li>tls.imirhil.fr (tests configured SSL\/TLS cipher suites).<\/li>\n<\/ul>\n<p>If you are familiar with SSL, you likely know <a href=\"https:\/\/www.ssllabs.com\/index.html\">SSL Labs<\/a> (by Ivan Ristic and Qualys), the most popular tool for testing your site\u2019s SSL configuration, and one that we strongly endorse. Observatory by Mozilla is a great companion to SSL Labs, and they have surprisingly little overlap in functionality.<\/p>\n<p>Observatory performs a basic assessment of your SSL\/TLS configuration. SSL Labs provides much more depth on SSL\/TLS issues, including any problems with your site\u2019s certificate chain, vulnerability to known attacks, or what user agents are unable to connect to your site. If you have the time (and curiosity), you should use both tools to get the best picture of your site\u2019s security.<\/p>\n<p>Observatory is available now,\u00a0<a href=\"https:\/\/observatory.mozilla.org\/\">so start scanning for free<\/a>! It\u2019s maintained as an <a href=\"https:\/\/github.com\/mozilla\/http-observatory-website\/\">open-source project on Github<\/a> and includes a <a href=\"https:\/\/github.com\/mozilla\/http-observatory-cli\">command line interface<\/a> utility.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>The free tool checks a site\u2019s SSL configuration and more. blog post on her personal site, King wrote \u201cthere wasn\u2019t one place to go for site operators to learn what&#8230;<\/p>\n","protected":false},"author":2,"featured_media":2986,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":"","tve_updated_post":"","tve_custom_css":"","tve_user_custom_css":"","tve_globals":{},"tcb2_ready":0,"tcb_editor_enabled":0,"tve_landing_page":"","_tve_header":"","_tve_footer":""},"categories":[17],"tags":[192,193,136],"class_list":["post-2985","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-industry-lowdown","tag-mozilla","tag-observatory","tag-ssl","post-with-tags"],"views":12660,"jetpack_featured_media_url":"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2016\/08\/Depositphotos_105006336_m-2015.jpg","_links":{"self":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts\/2985","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/comments?post=2985"}],"version-history":[{"count":0,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts\/2985\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/media\/2986"}],"wp:attachment":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/media?parent=2985"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/categories?post=2985"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/tags?post=2985"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}