logoalt Hacker News

Ellipsis753last Tuesday at 7:38 PM1 replyview on HN

Old links to your site might still be http - HSTS prevents that request being in the clear. Also, if you have a man-in-the-middle attack, it doesn't matter if you return a redirect or not as the attacker has already replaced your site with a phishing attack instead of a redirect. HSTS prevents this.


Replies

RamRodificationlast Tuesday at 8:45 PM

Your second example would also be prevented by just not serving on port 80 as the parent comment suggests, no?

show 3 replies