logoalt Hacker News

ocdtrekkielast Tuesday at 9:54 PM2 repliesview on HN

HSTS remains a broken antifeature which violates the covenant of a browser agent being a browser agent. (A server should never have more authority than me on dictating how my agent works.)

Firefox refuses to support the ability to bypass HSTS which generally means I'm forced to use a different browser when HSTS is getting in the way of me doing my job.

(Thankfully or unfortunately, Chromium-based browsers violate the HSTS spec and allow bypass. But there seems to be no appetite to actually repair the HSTS spec to permit this.)


Replies

winstonwinstonlast Tuesday at 10:30 PM

> Chromium-based browsers violate the HSTS spec and allow bypass.

If you were able to bypass HSTS using google chrome, that sounds like a bug.

show 1 reply
SkyPuncherlast Tuesday at 10:22 PM

When does HSTS get in your way?

show 2 replies