December 2, 2017

Security updates

  • We are now disallowing TLS 1.0 and legacy cipher suites
  • Configured httponly / secure flag for session and other secure cookies
  • Disallowed protected subdomains to be used by customers