Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Nitpick: HSTS doesn't interfere with MITM. You're thinking of certificate pinning.


You are right, I was thinking of stapling but wrote HSTS. Thanks


HSTS interferes with MITM when the mobile device in question doesn't allow you to install new certificate authorities (as is slowly becoming the case).




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: