Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Yes, no redirect can protect the user from that. In fact, not even completely disabling HTTP can - the ISP can respond on port 80 anyway. But it can protect them if they open it on a safe connection and then bookmark the page, or keep the tab open, or send the link to someone else, and then use that link on an unsafe connection.


Or using HSTS (especially with HSTS preloading)




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: