RoastMyOpsec

Blog

News OPSEC guides

OPSEC signal for public sites and apps — what changed, what still leaks, and what to scan first. Ten guides per page.

Page 7 of 7

News · Mar 2, 2022

AMP vs Signed HTTP Exchanges for Public Pages

AMP vs Signed HTTP Exchanges for public pages is two ways a third party might serve a copy of your HTML. AMP is a constrained HTML dialect historically cached on a Google origin (cdn.ampproject.org and cousins) — extra…

Read guide →

News · Feb 21, 2022

Alt-Svc vs Origin IP Exposure on CDNs

Alt-Svc vs origin IP exposure on CDNs is a performance header versus a bypass map. Alt-Svc (RFC 7838) tells supporting browsers they may use another protocol or host for this origin — commonly h3=":443" for HTTP/3 on…

Read guide →