|
|
|
|
|
by hywel
2594 days ago
|
|
This will leave your users vulnerable to man-in-the-middle attacks. If I control the router between their computer and the Internet, I can serve back a HTTP page which doesn't redirect, and trick them to enter their password (for example). HSTS is designed to prevent this. |
|