Y
Hacker News
new
|
ask
|
show
|
jobs
by
thirsteh
4558 days ago
It's necessary for HTTP requests. Are you being deliberately obtuse?
1 comments
ars_technician
4558 days ago
It doesn't work if the user hasn't visited the site before because the HSTS header can be stripped just as easily.
link
lvh
4558 days ago
The HSTS specification tells you not to put those headers in regular HTTP requests anyway.
Also, you're forgetting about browsers that ship with lists of HSTS-enabled sites.
link
gtklocker
4558 days ago
https://news.ycombinator.com/item?id=6978539
link