Hacker News new | ask | show | jobs
by jake_the_third 3023 days ago
That's what EFF's HTTPS Everywhere plugin does when set to strict mode.

On a related note, would strict mode thwart HSTS-based cookies?

My current understanding of this technique is that it depends on the victim being able to connect to HTTP. Since strict mode prevents the victim from making normal HTTP connections, I'm inclined to believe that strict mode does help mitigate this kind of tracking.

1 comments

I remembered a demo showing HSTS's potential tracking capabilities, and it doesn't work well if HTTPS Everywhere is enabled.