Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Does the HSTS list store the signature? Seems like if you see an HSTS site later convert to self-signed, that's always a security breach.


> Does the HSTS list store the signature?

It doesn't matter. The ONLY thing HSTS does is tell the browser to make future requests over HTTPS. If an HSTS site switches to a self-signed cert between my visits, the browser will still get warn me, because the new cert is suspicious.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: