Unterhaltung
Nachrichten
-
Another browser detection #fail https://hackerone.com/browser-not-supported.html #WhyDoPeopleDoThis
-
♻ Remon Oldenbeuving @R51: @BobJonkman In what browser are you seeing this?
-
@R51 It's not the browser. Sites should degrade gracefully, and still work when referers or browser ID strings or Javascript isn't available
-
♻ Remon Oldenbeuving @R51: @BobJonkman We introduced this redirect from a security standpoint. We intentionally block browsers that don't support XFO and HSTS headers
-
♻ Remon Oldenbeuving @R51: @BobJonkman so yes, I agree with you that sites should degrade gracefully when they can, but no, I don't think we can do that at this point.
-
♻ Remon Oldenbeuving @R51: @BobJonkman we can probably improve a lot on browser support and graceful degradation though, so if you have any tips, let me know!
-
@R51 Is https://hackerone.com 1) actually checking for XFO and HSTS capability, or 2) merely (mis)identifying the User Agent?
-
@R51 If 1) then provide that detail in the error message for us techs, eg. "HSTS support required, but not detected"
-
@R51 Also, I see that https://hackerone.com is completely #Javascrippled; nothing on the page except an error message, not even a logo
-
@R51 For secure browsers that choose not to use #Javascript, can you provide at least the site name, description and logo?
-
@R51 Remon, thanx for responding, and being so open to feedback! https://hackerone.com
-