Hacker News new | ask | show | jobs
by thirsteh 4558 days ago
It's necessary for HTTP requests. Are you being deliberately obtuse?
1 comments

It doesn't work if the user hasn't visited the site before because the HSTS header can be stripped just as easily.
The HSTS specification tells you not to put those headers in regular HTTP requests anyway.

Also, you're forgetting about browsers that ship with lists of HSTS-enabled sites.