Hacker News new | past | comments | ask | show | jobs | submit login

It doesn't work if the user hasn't visited the site before because the HSTS header can be stripped just as easily.



The HSTS specification tells you not to put those headers in regular HTTP requests anyway.

Also, you're forgetting about browsers that ship with lists of HSTS-enabled sites.





Consider applying for YC's Spring batch! Applications are open till Feb 11.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: