4 ms·
I've seen this issue in Firefox Nightly when trying to perform the HSBC UK credit card verification, so it makes sense not to roll it out to the wider public ye
by rolodato 8y ago
I've seen this issue in Firefox Nightly when trying to perform the HSBC UK credit card verification, so it makes sense not to roll it out to the wider public yet.
- computerfriend 8y agoOr the opposite, that people will unknowingly transmit data over untrusted connections without this.
- ticoombs 8y agoThey can't. With most banks and even PayPal, their site is secured by HSTS which renders their site completely unusable with no way to get past the warning. Your only option is to use a _different_ browser which trusts the old certificate.
- regecks 8y ago> no way to get past the warning. You are right, but there's always a chance that the various documented HSTS bypasses might filter down to normal people. People might be willing to find and use them if they /really/ need access to the site. e.g. Typing "thisisunsafe" in Chrome on the error screen, or flushing the HSTS state in the browser.
- LeoPanthera 8y agoPayPal just switched to a DigiCert certificate and should be accessible now.
- Vendan 8y agoOr to switch to a bank that actually cares about security?