Scott Helme
-
Report URI - outage update
This is not a blog post that anybody ever wants to write, but we had some service issues yesterday and now the dust has settled, I wanted to provide an update on what happened. The good news is that the interruption was very minor in the end, and likely went
Published
-
Integrity Policy - Monitoring and Enforcing the use of SRI
This has been a long time coming so I'm excited that we now have a working standard in the browser for monitoring and enforcing the use of SRI across your website assets!SRI refresherFor those that aren't familiar, or would like a quick refresher, here&
Published
-
CVE-2025-49844 - The Redis CVSS 10.0 vulnerability and how we responded
We're very public and open about our infrastructure at Report URI, having written many blog posts about how we process billions of telemetry events every single week. As a result, it's no secret that we use Redis quite heavily across our infrastructure, and some have asked
Published
-
Capture JavaScript Integrity Metadata using CSP!
Today we're announcing the open beta of a brand new and incredibly powerful feature on the Report URI platform, CSP Integrity! Having the ability to collect integrity metadata for scripts running on your site opens up a whole new realm of possibilities, and it couldn't be
Published
-
We're going High Availability with Redis Sentinel!
We've just deployed some mega updates to our infrastructure at Report URI that will give us much more resilience in the future, allow us to apply updates to our servers even faster, and will probably go totally unnoticed from the outside!Our previous Redis setupI've
Published
-
Automation improvements after a Tesla Powerwall outage!
So, a weird thing happened over the last couple of days, and my Tesla Powerwalls weren't working properly, or, at all, actually... What's even more strange is that Tesla has been completely silent about this and hasn't made a single announcement about the issue
Published
-
OWASP ASVS 5.0.0 is here!
I've been a huge fan of OWASP for a very long time, having spoken at their conferences, contributed to their projects, consumed many of their resources and met some really awesome people along the way! Just recently, one of the very popular OWASP projects, the Application Security Verification
Published
-
Trillion with a T: Surpassing 2 Trillion Events Processed!🚀🚀
We’ve just passed a monumental milestone: 2 trillion events processed through Report URI!!! That’s 2,000,000,000,000 events for CSP, NEL, DMARC, and other browser-generated and email telemetry reports—ingested, parsed, and processed for our customers!This is a phenomenal milestone to achieve
Published
-
V2: Hacking my Tesla Powerwalls to be the ultimate home energy solution!
In my first blog post about hacking my Tesla Powerwalls, I laid out all of the foundations and information about my home energy setup. You really need to read that blog post first as I'm going to be building on all of that work here, and assuming that
Published
-
Shorter certificates are coming!
Well, I was certainly hoping for this result, but wasn't necessarily expecting it! I'm pleased to report that Ballot SC-081v3 passed, and that shorter certificate lifetimes are now coming!The ScheduleI will go into more detail later in the post, but right now, let'
Published
-
Hacking my Tesla Powerwalls to be the ultimate home energy solution!
I've had solar and batteries at home for quite some time now, and despite my experience with them being really awesome, there were a few little things that were bugging me. Using systems from various different suppliers doesn't always provide the perfect integration, so I hacked
Published
-
PCI DSS FAQ SAQ WTF BBQ...
I was trying to come up with a sensible title for this blog post, but I feel this one mirrors the thoughts and feelings of many of us about recent events in the PCI DSS compliance space! There have been some significant changes in recent weeks, and with just 18
Published
-
Report URI: Launching Policy Watch and other improvements!
As we continue to expand and improve our offering, one particular area of focus over recent months has been on PCI DSS Compliance. Whilst 'compliance' might not be the first thing that many get excited about, the recent requirements introduced by the PCI SSC required some pretty solid
Published
-
Let's Encrypt to offer 6-day certificates!
Continuing their trend of radical change for the better, Let's Encrypt have announced that, this year, you will be able to request certificates with a validity period of only 6 days!Let's EncryptI remember sitting in the room for this DEF CON 23 panel discussion
Published
-
Updating to Pi-hole v6 and enabling HTTPS!
I first deployed my Pi-hole back in 2018 and ever since then, I've never looked back! Pi-hole have just dropped a pretty major update and, of course, I wanted to get HTTPS up and running on the Web UI like I had before. Pi-hole v6I won'
Published