Hacker News new | ask | show | jobs
by rolodato 2814 days ago
I've seen this issue in Firefox Nightly when trying to perform the HSBC UK credit card verification, so it makes sense not to roll it out to the wider public yet.
1 comments

Or the opposite, that people will unknowingly transmit data over untrusted connections without this.
They can't. With most banks and even PayPal, their site is secured by HSTS which renders their site completely unusable with no way to get past the warning.

Your only option is to use a _different_ browser which trusts the old certificate.

Or to switch to a bank that actually cares about security?
> no way to get past the warning.

You are right, but there's always a chance that the various documented HSTS bypasses might filter down to normal people. People might be willing to find and use them if they /really/ need access to the site.

e.g. Typing "thisisunsafe" in Chrome on the error screen, or flushing the HSTS state in the browser.

PayPal just switched to a DigiCert certificate and should be accessible now.