lesspass / lesspass

:key: stateless open source password manager
https://www.lesspass.com
GNU General Public License v3.0
5.76k stars 327 forks source link

lesspass.com HSTS preload status #671

Closed gmacar closed 3 years ago

gmacar commented 3 years ago

https://hstspreload.org/?domain=lesspass.com "Status: lesspass.com is currently preloaded, but no longer meets the requirements. It may be at risk of removal." For added security, it would be better to fix the error.

guillaumevincent commented 3 years ago

I'm going to fix this Thank you

guillaumevincent commented 3 years ago

I will push the change in production soon

May I ask how you detect this ? I would like to create a test to avoid this in the future

guillaumevincent commented 3 years ago

It has been fixed into production. Thank you for your vigilance

gmacar commented 3 years ago

I will push the change in production soon

May I ask how you detect this ? I would like to create a test to avoid this in the future

If you register lesspass.app, the HSTS preload status will be automatically checked and fixed by the TLD. This is what https://masterpassword.app does, for example.