3 ms·
It's important to note that even if the HSTS header was present on the mobile site, the exploit would still be possible since many mobile browsers do not suppor
by pmh 13y ago
It's important to note that even if the HSTS header was present on the mobile site, the exploit would still be possible since many mobile browsers do not support HSTS[1].
[1]http://michael-coates.blogspot.com/2013/09/security-capabilities-comparison-hsts.html http://michael-coates.blogspot.com/2013/09/security-capabili...