• foobaz@lemmy.world
    cake
    link
    fedilink
    English
    arrow-up
    4
    arrow-down
    1
    ·
    6 months ago

    I don’t think this is correct. HSTS only prevents downgrading.

    • ShellMonkey@piefed.socdojo.com
      link
      fedilink
      English
      arrow-up
      2
      ·
      6 months ago

      HSTS says it must be encrypted but a proxy will create two connections and look at it clear in the middle. On the other hand cert pinning says it must be a specific cert that breaks the site if decryption is used. Apple is big on doing that for a lot of their site and apps.