A 2026 study of 4,688 U.S. small-business websites found that 49.7% met none of seven security header criteria. HSTS was the most common header at 43.8% adoption, while X-Content-Type-Options: nosniff appeared on 39.7% of sites. Most other security headers showed poor adoption rates across the sampled directory-listed businesses.
Google demotes HTTP websites in search rankings to force adoption of HTTPS encryption, claiming security benefits. While HTTPS protects data confidentiality and authenticity, the article argues the transition imposes significant costs on users with slow connections and smaller websites lacking Google's infrastructure resources.
A user in Amsterdam describes using Chisel, an open-source tool that tunnels TCP and UDP traffic over HTTP and WebSocket, to bypass their hotel's restrictive firewall that blocks WireGuard and other services. The article provides installation and configuration instructions for running Chisel as both server and client, including setup with a reverse proxy like Caddy.
The author discusses the challenge of documenting and explaining technical concepts for learners transitioning from novice to expert, using Minecraft modding and web technology as examples. They argue that most resources cater to either complete beginners or experts, leaving a gap for intermediate learners who need to understand the underlying mechanisms and terminology.