Zendesk clocks 10,000 accounts accessed by miscreants before November 2016

not a secure website...

they lost peoples private TLS keys and then proceed to have a website that has :

No DNSSEC - its 2019 and yes acking dns is a thing

No IPv6 - 464xlat needed to access from a mobile device.

No SRI or complete CSP - no signing external resources I mean no one outside would include any problems in their javascript

easy to fix yet not done for some reason ?

