Hacker News new | ask | show | jobs
by XMPPwocky 3721 days ago
But then, if I'm MITMing you, I can just silently keep you on www, without SSL, without caring about HSTS or anything.
1 comments

If WordPress enables (preloaded) HSTS, that would not matter.