Hacker News new | ask | show | jobs
by EricButler 5524 days ago
An attacker could intercept that initial http:// url and provide their own destination for the browser to visit instead. HSTS prevents this from happening once the domain is in the cache (or pre-loaded).