3 ms·
The only vulnerability left would be, as mentioned above, a client installing a browser that doesn't support HSTS.
by deaps 8y ago
The only vulnerability left would be, as mentioned above, a client installing a browser that doesn't support HSTS.
- tedunangst 8y agoIf your attack relies on getting the user to install your own browser, don't waste your time with a simple HSTS bypass.