4 ms·
My personal grief with HSTS is that it pretty much requires you to have installed and trusted one random 400 CA collection or the other. If you have uninstalled
by mioelnir 10y ago
My personal grief with HSTS is that it pretty much requires you to have installed and trusted one random 400 CA collection or the other. If you have uninstalled/distrusted most of them, no current browser will allow you to access a HSTS enabled domain using one of those distrusted CAs.
There is no override to skip and accept an encryption-only connection. Which is what I would have gotten with HSTS as well, because without independent verification the CA system is a lot, but not the mutually trusted third party it claims to be.
- pfg 10y agoI'm quite happy that there's no way to bypass the intersitial for HSTS sites. Preventing non-technical users from clicking through SSL warnings (which is very common) is definitely more important than supporting a use-case that only affects a very, very small subset of users. If there's enough demand, I'm sure someone's going to introduce a hidden flag or some kind of extension that allows you to do this.
- mioelnir 10y agoI understand why it is done; and that the new error pages that are not filled with technical details are a net win overall. But there are people out there that need those technical details, so that other people do not have to see them.
- ryan-c 10y agoChrome at least, does allow HSTS errors to by overridden (and "safe browsing" warnings). It's just not exposed visibly. There is a deliberately undocumented "cheat code" that you need to type.
- mioelnir 10y agoIf you mean the one starting with D, then I may have mistyped and need to try that again. Thought that did not work for the HSTS block.
- ryan-c 10y agoThey've changed the code from that, the new one starts with B.
- mmastrac 10y agoWhat is this code?
- ryan-c 10y agoI intentionally didn't mention it. You should be able to find it from what I said if you really need it.