top | item 13326809

(no title)

jp3141 | 9 years ago

even with HSTS?

discuss

order

edeirme|9 years ago

If a website employs the use of HSTS all traffic will be redirected to HTTPS, rendering the support for HTTP redundant.

marichards|9 years ago

Hmm, if you can control the plaintext network isn't there an NTP attack to reverse time and use old compromisable certificates or move it forward past hsts max age?