|
|
|
|
|
by shawnz
2527 days ago
|
|
The argument here is that enabling HSTS can be dangerous because if you enable it and then later become unable to serve HTTPS for some reason, you will have no way of turning it off. Even if you get your clients to manually edit their bookmarks to use HTTP again, their browsers will just rewrite the url to HTTPS anyway. There's no issue with switching FROM HTTP to HTTPS: that's easy, just redirect them. The issue is if you have to switch back. |
|