Hacker News new | past | comments | ask | show | jobs | submit login

Issues with HSTS is that it is opt in. It should be an opt out with a list of legacy sites that ships with the browsers similar to how hsts preloading works.



The option browser vendors are going with seems to be to make http show a full page warning about being insecure. No need to change HSTS now.




Join us for AI Startup School this June 16-17 in San Francisco!

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: