TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Ask HN: Why would using HSTS be a disadvantage?

2 点作者 kaushikt将近 5 年前
I came across this well written post about some of the dangers of HSTS - https:&#x2F;&#x2F;www.tunetheweb.com&#x2F;blog&#x2F;dangerous-web-security-features&#x2F;#:~:text=I%20like%20HSTS%2C%20I%20think,slowly%2C%20you%20should%20be%20ok.<p>Even on Cloudflare, when you enable HSTS, it gives you a warning.<p>Generally, I have researched and learnt that HSTS is important to get secure by forcing all communications to happen via HTTPS.<p>So, why is everyone still giving so many warnings? Do orgs have a lot of HTTP setup for let&#x27;s say their APIs or legacy codes still supporting HTTP?

1 comment

detaro将近 5 年前
&gt; <i>I came across this well written post about some of the dangers of HSTS [...]</i><p>Doesn&#x27;t the article give a good explanation of why it recommends caution?