Sign in

Scott Helme

@scotthelme.bsky.social
2.7K followers 22 following 101 posts

Hi, I'm Scott Helme, a Security Researcher, Entrepreneur and International Speaker. I'm the creator of Report URI and Security Headers, and I deliver world renowned training on Hacking and Encryption. scotthelme.co.uk

PostsRepliesMedia
Scott Helme @scotthelme.bsky.social · 23/09/2026
A bunch of these domains went from first registration to being flagged in our threat intel feed in just 30 hours! There's a massive IoC list at the end of the post 💪
161
Scott Helme @scotthelme.bsky.social · 22/09/2026
It's pretty awesome to have this rolled out to 100% of users already!! 🤩
131
Scott Helme @scotthelme.bsky.social · 16/09/2026
It's so cool when you see something you built working exactly as intended 😎
030
Scott Helme @scotthelme.bsky.social · 15/09/2026
If you want a free @report-uri.bsky.social account during the beta, and then 50% off your first year as a thankyou, check out our new Magento CSP module in beta! 😎
010
Reposted by Scott Helme
Joe Tidy BBC News @joetidy.bsky.social · 07/09/2026
Great bit of research here from @scotthelme.bsky.social who decided to put a hacking group's story to the test. The criminals who hacked the three UK airports boasted about how easy it was and Scott checked the receipts. Apparently it was EXTREMELY basic stuff: scotthelme.co.uk/no-hacking-r...
scotthelme.co.uk
No Hacking Required: The Manchester Airports Group Data Breach
On 27 August 2026, Manchester Airports Group told customers that "an unauthorised third party" had stolen their data. Car park bookings, lounge bookings, Fast Track purchases for airport security and ...
284
Scott Helme @scotthelme.bsky.social · 07/09/2026
They exposed data on 8.8 million people with no exploit, no malware, and no access to MAG’s servers. Three server-side API keys sat in public JavaScript for 4+ years and FulcrumSec found them. They could have modified and deleted data too. scotthelme.co.uk/no-hacking-r...
scotthelme.co.uk
No Hacking Required: The Manchester Airports Group Data Breach
On 27 August 2026, Manchester Airports Group told customers that "an unauthorised third party" had stolen their data. Car park bookings, lounge bookings, Fast Track purchases for airport security and…
1154
Scott Helme @scotthelme.bsky.social · 06/09/2026
OK, it's not brilliant and the setup needs some work, but I got my first real data down from the weather satellite this morning! It's a homemade antenna on the roof, into a £40 dongle and a raspberry pi. The satellite was METEOR-M2 3, 838 km overhead(!), on 137.9 MHz.
080
Scott Helme @scotthelme.bsky.social · 05/09/2026
AOS!!! Weather satellite image download, first attempt. 137.9 MHz — Meteor-M N2-4 Dipole antenna @ 120°, aimed north Raspberry Pi 4B + £40 USB dongle Thirteen minutes as it passes 800 km overhead. No idea yet whether it'll work...
100
Scott Helme @scotthelme.bsky.social · 04/09/2026
Alright this is seriously awesome!! 🤩
040
Scott Helme @scotthelme.bsky.social · 03/09/2026
How can you possibly know your website is secure if you don’t know what code is actually running in your users’ browsers?! It seems like such a basic question, but most organisations simply can’t answer it. Now you can!
020
Reposted by Scott Helme
Report URI @report-uri.bsky.social · 01/09/2026
🚀 Connection Allowlist is now in open beta at Report URI! Build an egress firewall directly into the browser: control where pages can connect, block unauthorised destinations and detect attempted data exfiltration. Learn more and try it now 👇 blog.report-uri.com/connection-a...
blog.report-uri.com
Connection Allowlist: an egress firewall for the browser
Until now, malicious code running in a browser has had several ways to send data somewhere it shouldn’t, including new channels that CSP cannot fully cover and channels that do not even appear in the ...
012
Scott Helme @scotthelme.bsky.social · 24/08/2026
I recently completed a 1,600+ mile road trip around Europe, and these two bits of kit performed exceptionally well! 😎 scotthelme.co.uk/the-ultimate...
scotthelme.co.uk
The ultimate road trip combo: Starlink Mini + UniFi Travel Router
I recently went on an epic road trip around Europe, covering 1,645 miles (2,647 km), and we took in some amazing sights and locations. As a tech geek, I was worried about my connectivity on the trip,…
110
Scott Helme @scotthelme.bsky.social · 21/08/2026
I've just built and released a free tool: dbsc.dev Now you can check if your browser supports Device Bound Session Credentials! scotthelme.co.uk/introducing-...
dbsc.dev
Does your browser support DBSC?
A live test of whether your browser supports Device Bound Session Credentials (DBSC), showing the whole protocol exchange: the registration JWT, your device key, and a real session refresh.
021
Scott Helme @scotthelme.bsky.social · 11/08/2026
DBSC is now available in Chrome on macOS! 😎 It's currently rolling out in a Finch experiment and it looks like ~70% of people will have it already. scotthelme.co.uk/device-bound...
scotthelme.co.uk
Device Bound Session Credentials lands in Chrome on macOS
Device Bound Session Credentials (DBSC) is Chrome's answer to session cookie theft, usually by InfoStealer malware. Instead of a cookie being a bearer token that works anywhere it's pasted, DBSC…
010
Scott Helme @scotthelme.bsky.social · 10/08/2026
This is a bit of a 'stories from the trenches' post about building and deploying DBSC in a production app. If you're planning on taking DBSC for a spin, I'd recommend reading this first! scotthelme.co.uk/everything-i...
scotthelme.co.uk
Everything I Learned Shipping Device Bound Session Credentials
We shipped Device Bound Session Credentials at Report URI, open-sourced the server-side implementation, and then discovered a long list of things the specification doesn't prepare you for. Some…
010
Reposted by Scott Helme
Report URI @report-uri.bsky.social · 28/07/2026
Stripe just made CSP a compliance requirement. Merchants completing their annual PCI assessment are now asked to attest that they’ve deployed a Content Security Policy. That’s a major shift from “you should deploy CSP” to “confirm that you have.” Full details: blog.report-uri.com/stripe-now-a...
blog.report-uri.com
Stripe Now Asks You to Attest That You've Deployed a CSP
Stripe's PCI assessment now has a mandatory checkbox: confirm you've deployed a Content Security Policy. Here's what you're attesting to, and how to do it.
011
Reposted by Scott Helme
Report URI @report-uri.bsky.social · 23/07/2026
Onboarding just got a whole lot easier! 🤖 Using Claude, ChatGPT, Gemini, or another AI agent? Login, click "Copy Prompt", paste it into your AI, and it'll configure CSP reporting for you. Get up and running in minutes 😎 report-uri.com
011
Scott Helme @scotthelme.bsky.social · 22/07/2026
I've just updated whynopasskeys.com 🌍🔑 Thanks for the community input updating the directory! 💪
whynopasskeys.com
Why No Passkeys? — top sites without passkey support
20 of the world's top 50 websites still don't support passkeys. See the global list and per-country reports.
032
Scott Helme @scotthelme.bsky.social · 20/07/2026
We've released a new version of report-uri/dbsc-php thanks to community contributions! Full details: github.com/report-uri/d... Background: scotthelme.co.uk/open-sourcin...
github.com
Releases · report-uri/dbsc-php
Contribute to report-uri/dbsc-php development by creating an account on GitHub.
021
Scott Helme @scotthelme.bsky.social · 08/07/2026
This looks like it could be really promising! Connection Allowlist: a network firewall, built into the browser scotthelme.co.uk/connection-a...
scotthelme.co.uk
Connection Allowlist: a network firewall, built into the browser
Connection Allowlist is a new browser security mechanism that lets a document declare, up front, the exact set of destinations it's permitted to open network connections to. Anything not on the list…
092
Scott Helme @scotthelme.bsky.social · 07/07/2026
It hasn't changed in over a decade, so I've just given my captive portal buster a new look! 😎 httpforever.com
httpforever.com
HTTP Forever — A reliably insecure connection
A plain-HTTP page that helps you trigger captive portal login screens on public WiFi — on trains, in hotels, bars and on flights.
221
Scott Helme @scotthelme.bsky.social · 04/07/2026
Are there any other special TLDs that you’d like to see called out specifically? whynopasskeys.com#tlds
whynopasskeys.com
Why No Passkeys? — top sites without passkey support
18 of the world's top 50 websites still don't support passkeys. See the global list and per-country reports.
020
Scott Helme @scotthelme.bsky.social · 03/07/2026
Do we think these AI companies should have used AI to build passkey support into their sites? 🤖🔑 whynopasskeys.com/tld/ai
whynopasskeys.com
Why No Passkeys? — .ai sites
47 of the top 50 .ai websites don't support passkeys.
130
Scott Helme @scotthelme.bsky.social · 03/07/2026
I’ve just pushed an update to whynopasskeys.com It now covers the global top 50 sites and the top 50 for every country!
whynopasskeys.com
Why No Passkeys? — top sites without passkey support
18 of the world's top 50 websites still don't support passkeys. See the global list and per-country reports.
220
Scott Helme @scotthelme.bsky.social · 01/07/2026
10 years ago, I started analysing the security of the Top 1 Million websites. Here’s the state of web cryptography after a decade of observation! scotthelme.co.uk/top-1-millio...
scotthelme.co.uk
Top 1 Million Analysis – June 2026: The State of Crypto
This is part two of the ten-year anniversary Top 1 Million Analysis. Part one covered the broad state of the web — HTTPS, the security headers, cookies, email and DNS hygiene. This part is the bit I'v...
020
Reposted by Scott Helme
Troy Hunt @troyhunt.com · 30/06/2026
Weekly update is up! Live From Mallorca with @scotthelme.bsky.social - We’re talking passkeys and Claude Code: www.troyhunt.com/weekly-updat...
troyhunt.com
Weekly Update 510: Live From Mallorca with Scott Helme
How's the view?! Back to business, it's now 8 years ago that Scott and I thought it would be a cool idea to build Why no HTTPS? We used the site to shame companies for not implementing their transport...
032
Scott Helme @scotthelme.bsky.social · 29/06/2026
I can't believe it's been 10 years since I started my crawler project and analysed the security of the Top 1 Million sites!! scotthelme.co.uk/top-1-millio...
scotthelme.co.uk
Top 1 Million Analysis – June 2026: Ten Years of Web Security
It's been a long time since the last one of these! The previous Top 1 Million Analysis was way back in June 2022, and a lot has happened since then. But there's a much bigger reason to dust off the cr...
020
Scott Helme @scotthelme.bsky.social · 24/06/2026
Someone re-registered a former MaxCDN asset domain that thousands of websites still reference. They now control wildcard DNS across the old WP Engine namespace. It isn’t exploitable today—but that could change at the drop of a hat... scotthelme.co.uk/a-dead-cdn-a...
scotthelme.co.uk
A dead CDN, a wildcard, and an attack waiting to happen: the netdna-ssl.com takeover
Every now and then I go digging through Report URI's Threat Intelligence data feeds, looking for domains that show up in CSP reports where they really shouldn't. Last week one jumped out at me: netdna...
001
Scott Helme @scotthelme.bsky.social · 23/06/2026
Thanks for all the feedback, I've made some changes and just deployed new data 🔑 whynopasskeys.com
whynopasskeys.com
Why No Passkeys? — top sites without passkey support
6 of the world's top 25 websites still don't support passkeys. See the global list and per-country reports.
010
Scott Helme @scotthelme.bsky.social · 22/06/2026
7 of the world’s top 25 websites still don’t support passkeys. Why No Passkeys? tracks adoption across the biggest sites globally—and highlights who’s still missing out. whynopasskeys.com
whynopasskeys.com
Why No Passkeys? — top sites without passkey support
7 of the world's top 25 websites still don't support passkeys. See the global list and per-country reports.
144
Scott Helme @scotthelme.bsky.social · 15/06/2026
A single support ticket XSS became the front door to 275 million student records! scotthelme.co.uk/the-instruct...
scotthelme.co.uk
The Instructure Canvas Breach (2026): How XSS in a Support Ticket Compromised 275 Million Students
A single support ticket became the front door to 275 million student records. The Canvas breach shows how quickly untrusted user content can become a serious security incident when it is rendered insi...
030
Scott Helme @scotthelme.bsky.social · 02/06/2026
Cookies are still one of the weakest links in Web security! Device Bound Session Credentials could change that. scotthelme.co.uk/device-bound...
scotthelme.co.uk
Device Bound Session Credentials: Making Stolen Cookies Useless
A stolen session cookie can be vastly more powerful than a stolen password. The attacker doesn’t need to phish the user, bypass MFA, or defeat their passkey; they simply replay the cookie and step str...
040
Scott Helme @scotthelme.bsky.social · 21/05/2026
Passkeys are supposed to be browser-enforced security. But what happens when a browser extension can step into the WebAuthn flow and bypass the rules your site explicitly set? I dug into 1Password, Permissions Policy, and a questionable edge case: scotthelme.co.uk/passkeys-per...
scotthelme.co.uk
Passkeys, Permissions Policy and Bug Hunting in 1Password's WebAuthn Wrapper
Passkeys are the best thing to happen to web authentication in years, but a passkey ceremony is only as secure as the stack enforcing it. The browser, the relying party, the authenticator, and any ext...
030
Scott Helme @scotthelme.bsky.social · 20/05/2026
Another piece of work this week to boost the adoption of passkeys online! We've open-sourced our WebAuthn server lib that we use at @report-uri.bsky.social in production 😎
062
Scott Helme @scotthelme.bsky.social · 19/05/2026
I fell down the rabbit hole on this one, and there are more blog posts coming this week and next on the research! XSS is always bad, but I didn't quite realise how bad.
062
Scott Helme @scotthelme.bsky.social · 18/05/2026
We have some pretty cool research coming out this week, here's the groundwork before we get started! 😎
031
Scott Helme @scotthelme.bsky.social · 15/05/2026
This was another piece of particularly crafty malware! Imagine having the level of access that the attackers had here, and then choosing to inject a JS keylogger. Sounds crazy, but there's a good reason for it.
020
Scott Helme @scotthelme.bsky.social · 07/05/2026
It's really quite awesome to see some of the new features and capabilities we're adding right now. 😎 Exciting times ahead! 💪
020
Scott Helme @scotthelme.bsky.social · 22/04/2026
Kind of crazy that after all the progress we’ve made with passwords, 2FA, and now passkeys, the end result is still just… a cookie! Attackers will follow the value and the path of least resistance, meaning shifting to abusing the authenticated session. Check out my blog post and new white paper!
131
Scott Helme @scotthelme.bsky.social · 22/04/2026
If you’re in Glasgow, come and say hi! 😎
020
Scott Helme @scotthelme.bsky.social · 20/04/2026
I love it! 🤩
010
Scott Helme @scotthelme.bsky.social · 18/04/2026
Is it a bird, is it a…. Wait, yes that’s a bird 🤣 (zoom in)
070
Scott Helme @scotthelme.bsky.social · 13/04/2026
This is quite an interesting piece of ongoing work!
030
Scott Helme @scotthelme.bsky.social · 07/04/2026
We've since found a few more extensions and flagged them with Google/Microsoft! 😎 Does anyone know how we can get these extensions taken down faster? They're still active!
011
Reposted by Scott Helme
Report URI @report-uri.bsky.social · 02/04/2026
Our founder has just published a write-up on having our Passkeys implementation independently security tested. Auth is too important to just ship and hope for the best, so we brought in the experts! scotthelme.co.uk/bringing-in-...
scotthelme.co.uk
Bringing in the experts; Having our Passkeys implementation Security Tested
We recently announced support for Passkeys on your Report URI account, and everyone should go and enable Passkeys for the amazing security benefits they offer. As a new implementation of an authentica...
011
Scott Helme @scotthelme.bsky.social · 30/03/2026
Our March update was a big one! 😎 🤖 API and MCP Endpoints 🔑 Passkeys support 📈 Report Sampling 🛡️ Integrity Suite 📋 Audit Trail 👀 Visual updates And loads more! blog.report-uri.com/newsletter-m...
blog.report-uri.com
Newsletter - Mar 2026
Both January and February were big months for us at Report URI HQ, and we have continued to push forwards in March! API and MCP endpoints - beta invites! 🤖 Starting out with what has to be our mos...
031
Scott Helme @scotthelme.bsky.social · 27/03/2026
I'm not one for hyperbole, but watching our first few customers get hands on with MCP access has shown just how transformational this will be! 😎
000
Scott Helme @scotthelme.bsky.social · 24/03/2026
I love getting stuck in to some proper technical work! 😎
020
Reposted by Scott Helme
Report URI @report-uri.bsky.social · 18/03/2026
We're starting to see some really positive results with more customers using our CSP Integrity feature! scotthelme.co.uk/leverage-our...
scotthelme.co.uk
Leverage our treasure trove of Threat Intelligence data
We've been working on CSP Integrity for a little while now, and it was only announced in open beta back in September. Since then, as more of our customers start to use it, we've continued to improve i...
021
Scott Helme @scotthelme.bsky.social · 17/03/2026
The new reduced limit of 200 days validity for certificates landed over the weekend and, so far, all seems good! scotthelme.co.uk/shorter-cert...
scotthelme.co.uk
Shorter certificates are coming!
Well, I was certainly hoping for this result, but wasn't necessarily expecting it! I'm pleased to report that Ballot SC-081v3 passed, and that shorter certificate lifetimes are now coming! The Sche...
040