3 ms·
Because, the user's browser will remember that it should be HTTPS. With HSTS the user's browser will refuse to go to the HTTP at all. Thats how HSTS works, the
by bitexploder 12y ago
Because, the user's browser will remember that it should be HTTPS. With HSTS the user's browser will refuse to go to the HTTP at all. Thats how HSTS works, the browser remembers that the site has the HSTS setting.
HSTS also prevents the overriding of the bad certificate message. It is like anti-ssl strip. HSTS is harder to get around than this :)
- mike-cardwell 12y agoI know how HSTS works. I was responding to the claim that offering a HTTP service which redirects to HTTPS somehow reduces security, even when HSTS is in use.