Hacker News new | past | comments | ask | show | jobs | submit login

A preload does not require the header to be set. It would obviously be the smart thing to do, but it's not required.

HSTS is only a header.




A preload does not require the header to be set.

did you read evilpie's link?

"Only if a host responds with a valid HSTS header with an appropriately large max-age value (currently greater than or equal to 10886400, which is eighteen weeks) do we include it in our list. ... We limit the list to hosts that send a large max-age under the assumption that these sites will not revert to non-HSTS status."


but you obviously can't check every domain in the TLD. A preload will still function, that's the whole point: make sure a MITM can't cut off the HSTS header.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: