3 ms·
Chrome and Firefox both have a preloaded list of sites that should always use HSTS. https://blog.mozilla.org/security/2012/11/01/preloading-hsts/ https://blog.m
by evilpie 12y ago
Chrome and Firefox both have a preloaded list of sites that should always use HSTS. https://blog.mozilla.org/security/2012/11/01/preloading-hsts/ https://blog.mozilla.org/security/2012/11/01/preloading-hsts...
- bpatrianakos 12y agoRight but site owners need to request inclusion on that list only after they've enabled HSTS on the server. I've done this myself and I must say I'd be pretty angry if browsers forced an entire TLD to require HSTS. The result would be SSL warnings everywhere.
- tptacek 12y agoThat's why he's suggesting that the new TLDs do this, to start early, so that everyone's expectations are set properly.
- iancarroll 12y agoA preload does not require the header to be set. It would obviously be the smart thing to do, but it's not required. HSTS is only a header.
- rgbrenner 12y agoA preload does not require the header to be set. did you read evilpie's link? "Only if a host responds with a valid HSTS header with an appropriately large max-age value (currently greater than or equal to 10886400, which is eighteen weeks) do we include it in our list. ... We limit the list to hosts that send a large max-age under the assumption that these sites will not revert to non-HSTS status."
- iancarroll 12y agobut you obviously can't check every domain in the TLD. A preload will still function, that's the whole point: make sure a MITM can't cut off the HSTS header.