Re: Redirects and HSTS

On Fri, Sep 26, 2014 at 10:40 PM, Ryan Sleevi <sleevi@google.com> wrote:
> For HSTS, the question is "Could a MITM attacker gain access to the data
> otherwise"

Right.


> If we took away the +HSTS part
> - Source document HTTP, target document HTTP
>   - The attacker can read the target document on the wire

I see, we are assuming a HSTS setup where you do not redirect port 80.
That seems rather stupid. In that case I agree you would lose out.


-- 
https://annevankesteren.nl/

Received on Saturday, 27 September 2014 06:34:04 UTC