logoalt Hacker News

kiririnyesterday at 2:55 AM1 replyview on HN

Even with default https etc, HSTS still adds some defence against MITM - browsers won’t let you even forcibly accept a self signed certificate


Replies

AlotOfReadingyesterday at 3:10 AM

The number of MITM attacks that's thwarted for me remains zero, while sites forgetting to renew their certs despite setting HSTS is a fairly regular occurrence.

show 2 replies