|
It's definitely worth repeating the warning that, while very useful, Strict-Transport-Security should be deployed with special care! While the author's example of `max-age=3600` means there's only an hour of potential problems, enabling Strict-Transport-Security has the potential to prevent people from accessing your site if for whatever reason you are no longer able to serve HTTPS traffic. Considering another common setting is to enable HSTS for a year, its worth enabling only deliberately and with some thought. |
That might not be something that a company's management team wants to hear, but indicating to your users that falling back to insecure HTTP is just something that happens sometimes and they should continue using your site is one of the worst things you can possibly do in terms of security.