Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

The better solution is HSTS, which would tell the browser to use HTTPS for the site for the next year.

The main browsers come with a list of known HSTS sites, so you'll never use HTTP to access google.com (etc).

https://en.wikipedia.org/wiki/HTTP_Strict_Transport_Security



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: