freedomofpress / securethenews

An automated scanner and web dashboard for tracking TLS deployment across news organizations
https://securethe.news
GNU Affero General Public License v3.0
100 stars 29 forks source link

Jornal O Globo issue #285

Closed gusgustavo closed 3 years ago

gusgustavo commented 3 years ago

Hi, I was checking the results, and it seems weird that the Security Rating of "Jornal O Globo" is F: https://securethe.news/sites/jornal-o-globo

They do have a valid HTTPS. I also looked at SSLLabs, and they have a "B." https://www.ssllabs.com/ssltest/analyze.html?d=oglobo.globo.com

I also couldn't find O Globo URL (https://oglobo.globo.com/) in this file: https://github.com/freedomofpress/securethenews/blob/prod/news_sites.csv

Thanks!

conorsch commented 3 years ago

Hello, @gusgustavo ! Thanks for your interest. You're right, the results for "Jornal O Globo" aren't what I'd expect. Can't say precisely why that is at the moment, but we'll look into. Occasionally some sites with a subdomain show non-standard behavior, which we should fix—but that's just a guess, at the moment.

I also couldn't find O Globo URL (https://oglobo.globo.com/) in this file

For managing scanned sites, we have a private login page and make the edits directly on the site. That's confusing, and we should update the application's deployment settings to read in the csv so we can merge PRs to add new sites (preferably with region tags, now that #91 is resolved.

conorsch commented 3 years ago

Journo O Globalo is now reliably scoring a B+, rather than an F, which looks accurate to me: https://securethe.news/sites/jornal-o-globo Thanks for reporting this issue, @gusgustavo. Looks like once we resolve #225, we'll close the gap on news sites being added and then briefing showing an inaccurate result. In the meantime, we'll coordinate updates to keep the data fresh.