Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Aren't most CDNs (at least, the ones likely to have popular resources on several sites) using the hsts preload list already?


Not all CDNs are HSTS preloaded, and this affects linking too. Pick any random popular site that is widely linked but not preloaded, and now it's more vulnerable.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: