|
|
|
|
|
by tptacek
5083 days ago
|
|
No. The whole idea of HSTS is that you can never trust the DNS; you assume that's the most likely way an attacker is going to MITM her victims. HSTS tells the browser to remember that from that point on, all connections to SERVER.NAME have to happen under a TLS session with a valid cert. |
|
(If I could vote for your time investment, please kindly consider commenting on that article before replying to this comment.)
Thanks again!
[1] http://www.isc.org/community/blog/201002/whither-dnscurve
[2] http://news.ycombinator.com/item?id=4268461