4 ms·
Is https enough or do we also need hsts? And how does QUIC fit into all of this?
by AtNightWeCode 4y ago
Is https enough or do we also need hsts? And how does QUIC fit into all of this?
- bastawhiz 4y agoPretty much all browsers will try HTTPS first if you type a URL without a protocol. HSTS only practically helps in the case where you have URLs that have the wrong protocol. QUIC and H2 are both always encrypted. But since quic is purely supplemental at this point, it really doesn't factor into anything relevant here.
- philsnow 4y agoThe reason to use https is because we assume there could be a malicious party between you and the site you're visiting. If we assume that, we should further assume that they will inspect SNI in your https request, see that you're visiting some domain they are interested in, and just block that request (or creatively fail to make a good https connection, to arouse less suspicion), causing your browser to helpfully fall back to plain http. But this is exactly the behavior we don't want. HSTS (or firefox's force https setting, probably similar settings exist for other browsers, or HTTPS Everywhere's strict setting) makes your browser insist on using https for connections to that domain, and showing an error page if it's not possible.
- AtNightWeCode 4y agoWhat I don't get is what is the purpose of HSTS if HTTPS is enforced in the first place. Several (most?) security checkers will warn if HSTS is not enabled for a site. From the tests I have done it seems impossible to get QUIC and HSTS to even work on the same site.
- tialaramex 4y ago> From the tests I have done it seems impossible to get QUIC and HSTS to even work on the same site. I don't understand, maybe you need to explain "the tests I have done" here ?
- AtNightWeCode 4y agoEnabling HTTP3 and HSTS on major cloud platforms like Cloudflare (Enterprise) and so on only seems to enable QUIC/HTTP3 and the HSTS headers are no where to be seen. Is HSTS even a thing?