3 ms·
This is why we have HSTS.
by flyt 13y ago
This is why we have HSTS.
- Sami_Lehtinen 13y agoAnd secure cookies, yes. But as we have seen, those things simply do not work out. As the usual layered security approach, it's good idea not to provide HTTP service at all, so redirection isn't hiding failures to use HTTPS.