logoalt Hacker News

SkyPuncherlast Tuesday at 10:22 PM2 repliesview on HN

When does HSTS get in your way?


Replies

ocdtrekkielast Tuesday at 11:32 PM

Most commonly when fixing certificate errors! A lot of modern web applications have all of their certificate configuration in the web interface... which you can't access when your certificate breaks. I think once I had to break out IE11 to fix a certificate because Firefox wouldn't let me...

But also sometimes I need to access a website where the certificate lapsed yesterday. This is not a security issue and no reasonable person would assume a certificate expired yesterday is compromised, but we are living in a world of madness. I am not going to wait for some third party to fix their site, I'm just going to circumvent HSTS, I have better things to do.

ycombinatrixlast Tuesday at 10:35 PM

When I'm unable to turn it off.