CSP/HSTS/HPKP (security headers) on Monzo.me

This (and the related CSP conversation) was a conscious initial decision made by Monzo - rather than an oversight. I raised it previously and @daniel made a few comments.

Though I don’t recall exactly what he said, he was already aware and basically I think it came down to a time/benefit balance. It doesn’t add a huge amount security-wise, although it is beneficial. It will likely be added at some point, along with HPKP.

I’m sure he’ll make a quick note if there is anything to add.

2 Likes