Hacker News new | ask | show | jobs
by jlgreco 4763 days ago
Or (in enough cases to be a valid concern), not without using sslstrip. Which is trivial.
1 comments

If you are the recipient of the link, SSL can't be stripped.

Even if you are an author, assuming you have visited the site over SSL at least once, then it can't be stripped on future visits since the site seems to use HSTS.

It is trivial to strip links being sent to a user over unsecured channels.

There are many things that can mitigate an sslstrip style attack, but coverage from those things is patchy.