3 ms·
Ideally, you should always use "includeSubdomains" with HSTS. This will provide robust security for the main hostname as well as all subdomains. The issue here
by ivanr 13y ago
Ideally, you should always use "includeSubdomains" with HSTS. This will provide robust security for the main hostname as well as all subdomains. The issue here is that (without "includeSubdomains") a man in the middle attacker can create arbitrary subdomains and use them inject cookies into your application. In some cases, even leakage might occur.
The drawback of "includeSubdomains", of course, is that you will have to deploy all subdomains over SSL.
- aroch 13y agoThanks, that's what I thought.