8 ms·
No. HSTS prevents SSLStrip attacks when the intended destination is always meant to be in SSL.
by netik 13y ago
No. HSTS prevents SSLStrip attacks when the intended destination is always meant to be in SSL.
- peterwwillis 13y agoSSLStrip does not work on valid HTTPS requests. If you request an HTTPS page, it can not be subverted into HTTP. If it could, HTTPS would be pointless. So, yes, HSTS is not required for a valid HTTPS request. This is not some semantic argument, or some sort of side channel attack crap. HSTS is not necessary for HTTPS requests, period.
- thirsteh 13y agoIt's necessary for HTTP requests. Are you being deliberately obtuse?
- ars_technician 13y agoIt doesn't work if the user hasn't visited the site before because the HSTS header can be stripped just as easily.
- gtklocker 13y agohttps://en.wikipedia.org/wiki/HTTP_Strict_Transport_Security#Applicability https://en.wikipedia.org/wiki/HTTP_Strict_Transport_Security...