Hacker News new | past | comments | ask | show | jobs | submit login

It's necessary for HTTP requests. Are you being deliberately obtuse?



It doesn't work if the user hasn't visited the site before because the HSTS header can be stripped just as easily.


The HSTS specification tells you not to put those headers in regular HTTP requests anyway.

Also, you're forgetting about browsers that ship with lists of HSTS-enabled sites.





Join us for AI Startup School this June 16-17 in San Francisco!

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: