Hacker News new | ask | show | jobs
by bvttf 3016 days ago
While I'd also like https as a default, that's not going to prevent this tracking if you still respect the intent of HSTS.

If you try https first, and that fails, do you try again over http? Whether or not you'd fallback would leak the same information.