Scott Helme
banner
scotthelme.bsky.social
Scott Helme
@scotthelme.bsky.social
Hi, I'm Scott Helme, a Security Researcher, Entrepreneur and International Speaker. I'm the creator of Report URI and Security Headers, and I deliver world renowned training on Hacking and Encryption.

https://scotthelme.co.uk
No, the crash reports are quite limited in that regard. Their main goal is to let you know something is happening that you might have no other way to find out about.
October 27, 2025 at 3:04 PM
We provide information on the steps for remediation, and link out to verified sources of information on the vulnerability if you'd like more information.
September 29, 2025 at 11:11 AM
Along with identifying the JS files on your site, we can also cross-check them against our database of Known Vulnerabilities, and flag when you're loading JS with serious issues!
September 29, 2025 at 11:11 AM
Of course, this also means that you can detect when/if those JS files change, as they will start reporting a new hash. This is a great way to be able to monitor for undesirable changes to 3rd-party dependencies.
September 29, 2025 at 11:11 AM
We've already built a database of almost 13,000,000 fingerprints that we have verified, meaning we can reliably identify files loading on your site.
September 29, 2025 at 11:11 AM
You can now fingerprint JS running on your site with a cryptographically secure hash function and have that data sent to report-uri.com This is native browser functionality, so there is no code to deploy anywhere!
September 29, 2025 at 11:10 AM
It has, but there's always an element of ongoing work. It's not just extensions, but corporate proxies/firewalls, AV software on the client, and anything that can interfere with the page.

Our filtering has become pretty good 👍
July 2, 2025 at 6:38 PM
To celebrate, we've just launched a seriously cool public dashboard that gives heaps of insight into our traffic! Check it out, and there is something in there I've wanted to build for a very long time:

scotthelme.co.uk/trillion-wit...
Trillion with a T: Surpassing 2 Trillion Events Processed!🚀🚀
We’ve just passed a monumental milestone: 2 trillion events processed through Report URI!!! That’s 2,000,000,000,000 events for CSP, NEL, DMARC, and other browser-generated and email telemetry reports...
scotthelme.co.uk
July 2, 2025 at 6:18 PM
Certificate renewal should be fully automated by then, and ideally by now already. Once renewal is automated, how often you renew really doesn't matter any more. I have no idea when any of my certificates renew, they just do it!
April 22, 2025 at 2:20 PM
I might like this version of the graph more! 🤔
April 22, 2025 at 2:19 PM
Well, hopefully, you wouldn't leave it so close to expiry, I'd probably recommend every 30 days.
April 22, 2025 at 2:15 PM
Here's what that looks like when viewing the full history, which shows we recently stalled out on our progress to shorter certificates, and even these new deadlines are a much reduced rate of progress:
April 22, 2025 at 1:42 PM
Straight to the point, here is the schedule for the reduction in certificate lifetimes!

March 15th 2026: All new certificates capped at 200 days validity

March 15th 2027: All new certificates capped at 100 days validity

March 15th 2029: All new certificates capped at 47 days validity!
April 22, 2025 at 1:41 PM
No, it hooks up to my DNS provider and sets DNS TXT records, I don't use the HTTP validation mechanism.
March 4, 2025 at 9:38 AM
Even if I switch to cellular data, or VPN to a new IP address altogether, they still don’t work. This is an example with my email signature, but no images work at all.
February 7, 2025 at 9:58 AM
It doesn't seem like rate limits make sense, and the status codes we're getting for images in our emails is a 403, not something like a 429 as I'd expect. We also don't send/receive that many emails so rate limits again don't sound very likely?
February 7, 2025 at 9:57 AM