Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Right, as long as it falls back to HTTP, you don't really increase security. And if you have a side-channel like preloaded HSTS lists the change does not apply. So you're right, it just makes HTTPS sites load faster.


Hmm so I thought about it a little and I think the old way allows passive monitoring of the URL within the website while the new way requires active attacks to enable this.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: