3 ms·
That response is crazy. If he's so set at keeping the homepage http, then make a download.keypass.com site and keep the downloads on there, with https required.
by deftnerd 10y ago
That response is crazy. If he's so set at keeping the homepage http, then make a download.keypass.com site and keep the downloads on there, with https required.
- 3pt14159 10y agoEh. Still vulnerable to HSTS attack. To me HTTPS without HSTS is only protection to programmers. To the public, HTTPS without HSTS protection is essentially useless against MITM attacks.