3 ms·
One primary example would be sites like software repository mirrors, where the majority of content is signed already, and serving them over HTTPS provides negli
by AfroThundr 9y ago
One primary example would be sites like software repository mirrors, where the majority of content is signed already, and serving them over HTTPS provides negligible benefit to your users (other than the slight confidentiality increase in that an adversary wouldn't know what exactly you downloaded), as opposed to a site serving active content like JavaScript and CSS, which can have disastrous results to the users if an adversary tampers with them.
The latter example is where HSTS becomes an invaluable tool, since now the only way those resources could be delivered is through a trusted channel, verified by the PKI. The same value is not there for a software mirror, because of the other security safeguards already implemented, removing the need to trust the delivery channel. That said, most still do server their content over HTTPS as well.