4 ms·
> There's still a privacy issue of your browser basically bookmarking every HSTS site that you visit, and probably not providing an easy way to know that happen
by thirsteh 13y ago
> There's still a privacy issue of your browser basically bookmarking every HSTS site that you visit, and probably not providing an easy way to know that happening or clear that out. For example, if I clear my browsing history, should it reset my HSTS lists?
Agree. I'm suggesting the client maintains an up-to-date bloom filter for all revoked certificates, and only contacts Google when something detects as positive (to verify that it is not a false positive.) You will still leak "I visited foo.com" if someone has compromised your SSL connection to google.com, but at least it doesn't leak your entire browsing history.