Re: [whatwg/fetch] Privacy-preserving HSTS (#920)

We've also considered just not applying HSTS to resources on an HTTP page - simpler and *probably* good enough, but that would mean we'd be making HTTP requests to entries in the HSTS-preload list, which seems suboptimal.  We could only upgrade requests for sites in the preload list, but that would make the preload list more powerful than it already is, which seems not great.

-- 
You are receiving this because you are subscribed to this thread.
Reply to this email directly or view it on GitHub:
https://github.com/whatwg/fetch/issues/920#issuecomment-535995532

Received on Friday, 27 September 2019 15:50:24 UTC