|
|
|
|
|
by Nikker
4433 days ago
|
|
Is this a different implementation of Diffie–Hellman? As far as I can tell (and I am likely wrong) there needs to be one successful connection attempt using a secure protocol, in this case HSTS, to detect if the redirect was indeed to the correct site or a MitM attack. |
|
[0] https://src.chromium.org/viewvc/chrome/trunk/src/net/http/tr...
[1] https://blog.mozilla.org/security/2012/11/01/preloading-hsts...