Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Definitely not a perfect solution -- all your points are definitely gaps in Strict Transport Security.

However, there's still a lot of value to adding HSTS. As for #1 and #2 and #3, HSTS is a standard that can and will be more broadly supported (and better implemented) over time probably more quickly than HTTP2 will be supported on most servers.

Personally, I'm most concerned about #4. This should be something the IETF should be working on (if they aren't already).

At the end of the day, if you've already mastered transport encryption, you may as well go forward with HSTS as well.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: