Hacker News new | ask | show | jobs
by deaps 2816 days ago
The only vulnerability left would be, as mentioned above, a client installing a browser that doesn't support HSTS.
1 comments

If your attack relies on getting the user to install your own browser, don't waste your time with a simple HSTS bypass.