Scott Helme

  1. V2: Hacking my Tesla Powerwalls to be the ultimate home energy solution!

    In my first blog post about hacking my Tesla Powerwalls, I laid out all of the foundations and information about my home energy setup. You really need to read that blog post first as I'm going to be building on all of that work here, and assuming that

    Published

  2. Shorter certificates are coming!

    Well, I was certainly hoping for this result, but wasn't necessarily expecting it! I'm pleased to report that Ballot SC-081v3 passed, and that shorter certificate lifetimes are now coming!The ScheduleI will go into more detail later in the post, but right now, let'

    Published

  3. Hacking my Tesla Powerwalls to be the ultimate home energy solution!

    I've had solar and batteries at home for quite some time now, and despite my experience with them being really awesome, there were a few little things that were bugging me. Using systems from various different suppliers doesn't always provide the perfect integration, so I hacked

    Published

  4. PCI DSS FAQ SAQ WTF BBQ...

    I was trying to come up with a sensible title for this blog post, but I feel this one mirrors the thoughts and feelings of many of us about recent events in the PCI DSS compliance space! There have been some significant changes in recent weeks, and with just 18

    Published

  5. Report URI: Launching Policy Watch and other improvements!

    As we continue to expand and improve our offering, one particular area of focus over recent months has been on PCI DSS Compliance. Whilst 'compliance' might not be the first thing that many get excited about, the recent requirements introduced by the PCI SSC required some pretty solid

    Published

  6. Let's Encrypt to offer 6-day certificates!

    Continuing their trend of radical change for the better, Let's Encrypt have announced that, this year, you will be able to request certificates with a validity period of only 6 days!Let's EncryptI remember sitting in the room for this DEF CON 23 panel discussion

    Published

  7. Updating to Pi-hole v6 and enabling HTTPS!

    I first deployed my Pi-hole back in 2018 and ever since then, I've never looked back! Pi-hole have just dropped a pretty major update and, of course, I wanted to get HTTPS up and running on the Web UI like I had before. Pi-hole v6I won'

    Published

  8. Stronger Than Ever: How We Turned a DDoS Attack Into a Lesson in Resilience

    Operating an online service like Report URI, it comes with the territory. The ever present threat of attack is something we are fully aware of, and prepare for as best we can. Being the regular subject of attacks, mostly handled by our robust systems and automated defences, these attacks mostly

    Published

  9. Let's Encrypt to end OCSP support in 2025

    Well, the writing has been on the wall for some years now, arguably over a decade, but the time has finally come where the largest CA in the World is going to drop support for the Online Certificate Status Protocol.What is OCSP?The Online Certificate Status Protocol is a

    Published

  10. XSS Ranked #1 Top Threat of 2024 by MITRE and CISA

    As we draw near the end of 2024, MITRE have taken a look back at the security vulnerabilities discovered throughout the year and published their list of the Top 25 Most Dangerous Software Weaknesses, and Report URI is here to help you with the #1 Top Threat: XSS.Common Weakness

    Published

  11. Report URI Penetration Test 2024

    It's that time of year again! At Report URI, we've just been through our 5th penetration test, and as usual, we're going to publish the results, take a look at what was found, and what we're going to do about it. Penetration

    Published

  12. Report URI: Simplifying pricing and changes to free accounts

    We've been making great progress on developing new features at Report URI recently, and over the coming months, you're going to see many of them launched! As we've expanded the team to achieve this, and as we want to continue to grow, we'

    Published

  13. Are shorter certificates finally coming?!

    Regular readers will know my views on the validity period of TLS certificates, and how they definitely need to be made shorter than they currently are! We made some good progress on reducing their lifetime over the last few years, but recently, that progress seems to have stalled out... Well,

    Published

  14. iOS 18 Quick Tips; Security Edition

    Having recently updated to iOS 18, there are a couple of features that I've immediately enabled now that they're available! I'm going to share with you what those features are, and, a security tip that has been available prior to the release of iOS

    Published

  15. Introducing Frame Watch: Monitor payment page activity with ease!

    For a long time, Report URI has been helping website owners deliver a more secure browsing experience for their users. With this latest release of a new feature, called Frame Watch, we're adding yet another capability to our platform to give you more visibility into payment processing on

    Published