Skip to content
PeekWellThe Rulebook
Join now

Website security best practices: HTTPS and open paths

At a glance

US-15Low15 U.S.C. §45; state security-safeguard statutes

Peeky reads whether your connection is encrypted and asks, by status code only, whether a short list of well-known sensitive folders and files answers from outside.

Last checked against the source:

I need to fix thisI need the rule

The rule

The United States has no single website security statute. The federal rule that reaches a company’s website is section 5 of the FTC Act, and it does not mention encryption, headers or file paths. The FTC builds the expectation case by case.

Section 45(a)(1) declares “unfair or deceptive acts or practices in or affecting commerce” unlawful. Section 45(n) limits the unfairness half: the Commission may not declare an act or practice unfair “unless the act or practice causes or is likely to cause substantial injury to consumers which is not reasonably avoidable by consumers themselves and not outweighed by countervailing benefits to consumers or to competition.”

So a security case under section 5 rests on three things: injury or likely injury to consumers, that consumers could not reasonably avoid, and a balance against the benefits. Security can also be handled as deception, when a company tells consumers its security is better than it is. The GoDaddy allegations below pair a security claim with the failures alleged behind it.

Whether the FTC can use unfairness for security at all was tested in court. The FTC’s own account of the Third Circuit’s ruling in FTC v. Wyndham, of 25 August 2015, says the court “upheld” that the FTC could use the prohibition on unfair practices in section 5 to challenge the data security lapses alleged, and rejected Wyndham’s argument that it lacked notice.

What the FTC expects in practice is in its guidance. “Start with Security” tells businesses to “use strong cryptography to secure confidential material during storage and transmission”, and names Transport Layer Security (TLS) encryption as one possibility. A lesson on configuration describes companies that used SSL encryption in their mobile apps but “turned off a critical process”, which made the apps open to interception. Another lesson, on access, describes a company that stored consumer information on a server on which it had disabled the firewall. The guide does not mention security headers, and nothing the FTC published that was read for this page names them.

The orders in the cases below require a security program and independent assessments, and one proposed order carried a payment for refunds. State laws add their own security duties and differ from state to state. This page covers the federal layer, and the state statutes were not read for it.

What PeekWell checks and how

US-15 asks two questions that a visitor’s browser can answer: is the connection encrypted and set up in the usual way, and do a few well-known sensitive paths answer from outside?

The first half is the same engine used for EU-15 and UK-15. The scan opens a public page the way an ordinary browser does, reads the TLS handshake and the response headers, and notes mixed content. It looks at HSTS, Content-Security-Policy and X-Frame-Options. The results are compared with a baseline.

The second half is specific to this check. The scan asks, for a short list of well-known paths, whether the server answers. The list covers things such as a source-control folder like .git/, an environment file like .env, backup files and open directory listings. For each path the scan records the HTTP status and whether the path exists, and nothing else. It never opens, reads or stores what a path returns, and a status code alone does not say what is there or whether it matters.

Code decides what is reported from those statuses and headers. A language model may help word the explanation and never decides that a path answered. The default severity is low, and the report states an observation, not a conclusion.

The scan has limits, and the report says so. It reads public pages and, for the path check, the status of a short list of addresses. It does not sign in, submit forms or test passwords. It does not try to get past a login, guess names beyond the list, or read the content of anything. It cannot see how data is stored or who inside the company can reach it. A Passed means the expected behaviour was observed on what was scanned. It does not say the site complies.

Why it matters for a company

For the FTC, the facts in these cases are not subtle. In several of them a file or a connection was reachable by anyone.

In the 2015 settlements with two debt brokers, Cornerstone and Company and Bayview Solutions, the FTC alleged that the companies posted unencrypted documents on a website geared for debt buyers, sellers and others in the industry, “but accessible to anyone with an internet connection”. The files held names, addresses, card and bank account numbers and amounts consumers allegedly owed, for about 55,000 consumers. The settlements require a security program, with assessments by an independent party at the start and every two years.

In the GoDaddy matter, finalized on 21 May 2025 by a 3-0 vote, the FTC alleged that the company claimed award-winning security while not using multi-factor authentication, not monitoring for threats and not securing connections to consumer data. The order bars misrepresenting security, requires a comprehensive security program and calls for an independent assessor. One commissioner concurred but dissented on one count.

A third example shows how long a gap can stay open. In June 2023 the FTC alleged that Vitagene, now 1Health.io, kept nearly 2,400 health reports and the raw genetic data of at least 227 consumers in unencrypted, publicly accessible cloud storage, and that over about two years it was told at least three times. The proposed order included $75,000 for consumer refunds.

For a company the practical points are these. The FTC’s pleadings treat “reachable by anyone” as a fact that can be shown. Telling customers your security is strong makes the gap a question about the claim as well as the control. And a warning that goes unanswered, as in the Vitagene allegations, is part of the story the FTC tells.

Smaller companies and larger companies

Section 5 has no size threshold. The FTC looks at injury and what the company could have done at reasonable cost.

In a small company the gap is usually a leftover. A developer deploys the whole repository to the web root, so .git/ answers. A backup is copied next to the site before an update and forgotten. An .env file with keys sits where the site is served from. Directory listing is on by default in the host’s setup. The site is on HTTPS, but a subdomain from an old campaign still answers on plain http. The 2015 settlements were with two firms each owned by an individual, but the FTC page gives no size for either, and the allegation was a public file area.

In a larger company the problem is scale. There are many hosts, staging sites that were never taken down, agency microsites and a CDN with different rules for different paths. The GoDaddy allegations show the other pattern: security claims made at brand level, with connections and controls that did not match them across a very large estate.

Enforcement cases

Published decisions about other companies, listed for context. Each links to the authority's own page. They say nothing about any particular website.

The Officer, squinting at a file.

Larger companies

  • GoDaddy Inc.

    FTC (United States), 2025Order to fix

    The FTC alleged that GoDaddy claimed to provide award-winning security while not using multi-factor authentication, not monitoring for security threats and not securing connections to consumer data. The order finalized in May 2025 requires a comprehensive security program, independent assessments and no misrepresentation of its security.

    Read the FTC (United States) publication about GoDaddy Inc.
  • Cornerstone and Company, LLC and Bayview Solutions, LLC

    FTC (United States), 2015Security program order

    The FTC press release gives no headcount or turnover for either company, so the size shown is only the schema's nearest value. The FTC alleged that two debt brokers, each owned by an individual named in the release, posted unencrypted files with names, addresses, card and bank account numbers and debt amounts for about 55,000 consumers on a website for the debt industry that was accessible to anyone with an internet connection. The settlements require a security program and independent assessments every two years.

    Read the FTC (United States) publication about Cornerstone and Company, LLC and Bayview Solutions, LLC

Smaller companies

No FTC security case against a company shown to be small, at the FTC's own page, was found for this check. The 2015 debt-broker press release names two LLCs and their owners but gives no size.

How to fix it

The steps follow the FTC’s lessons: protect data in transit with TLS, check your configuration, and restrict access to what is needed.

  1. Check your own paths first. From a terminal run curl -sI https://yourdomain.com/.env and the same for /.git/config, /backup.zip and any other file you can think of that should not be public. Look at the status line only. On your own site you can also look inside, and Peeky will not.
  2. Keep the repository and backups out of the web root. Deploy build output only. Move dumps, archives and .env files to a folder the server does not serve.
  3. Block dotfiles and version-control folders at the server. One rule in the server config is enough.
  4. Turn directory listing off. Set autoindex off in nginx or Options -Indexes in Apache.
  5. Treat anything that was reachable as read. If a path answered with a file that held keys or passwords, rotate them. Removing the file does not undo the time it was open.
  6. Fix transport and headers. Redirect http to https everywhere, allow TLS 1.2 and 1.3, add HSTS and content security headers as described in EU-15.
  7. Re-scan. Run a scan again and check the path and transport findings are gone.
location ~ /\.(?!well-known) { deny all; }
autoindex off;

This is a starting point. Whether it is enough for your data is a question for your adviser, and Peeky reports only what it sees.

Questions

What are website security best practices under US law?

No federal statute lists them. The FTC applies section 5 of the FTC Act, which bans unfair or deceptive practices, and its guidance and orders show what it expects: encrypt data in transit and in storage, limit access, and test the setup. States add their own rules, which differ.

Does the FTC regulate data security?

Yes, through section 5 of the FTC Act. In 2015 the Third Circuit held that the FTC can use the unfairness part of section 5 to challenge data security lapses. The FTC has brought many cases since, including GoDaddy in 2025.

What is the FTC's Start with Security guide?

It is the FTC's plain-language guide for businesses, built from lessons in its own cases. It tells companies to use strong cryptography, naming TLS, to protect sensitive data in transit, and to limit access to what each person needs.

What is a directory listing and why does it matter?

It is a web server page that lists the files in a folder, so anyone who finds the folder can see and open them. If the folder holds backups or private files, they become public. Peeky only records whether a known path answers, not what it holds.

Does Peeky look inside folders it finds?

No. For a short list of well-known paths, Peeky records the status code the server returns and nothing else. It never opens, reads or saves what is there. It also is not a security testing service and cannot be used as one.

Filed with

The rule

FTC Act section 5, 15 U.S.C. § 45(a)(1) and (n)

Read the rule (FTC Act section 5, 15 U.S.C. § 45(a)(1) and (n))

A case

GoDaddy Inc.

FTC (United States), 2025

Read the decision (GoDaddy Inc.)

Your site

Is your website affected? Join now to find out.

Join now

Sources

  1. 15 U.S.C. § 45, Unfair methods of competition unlawful (Cornell Legal Information Institute)
  2. FTC, Third Circuit rules in FTC v. Wyndham case, 25 August 2015
  3. FTC, Start with Security: A Guide for Business
  4. FTC, FTC Finalizes Order with GoDaddy over Data Security Failures, 21 May 2025
  5. FTC, Debt Brokers Settle FTC Charges They Exposed Consumers' Information Online, 13 April 2015
  6. FTC, FTC Says Genetic Testing Company 1Health Failed to Protect Privacy and Security of DNA Data, 16 June 2023
  7. FTC, In the Matter of 1Health.io Inc., complaint, Docket No. C-4798
  8. FTC, Auto Dealer Software Provider Settles FTC Data Security Allegations, 12 June 2019

Last checked against the source:

For information only. Not legal advice.