logo

HSTS - A Trivial Response to sslstrip

ID: e48210b4-53d2-5c8e-bbe5-68416cd67a8b

STIX ID: report--e48210b4-53d2-5c8e-bbe5-68416cd67a8b

Feed Name: WatchGuard Secplicity Blog

Date Published: 2019-11-05

Date Updated: 2026-05-01

Author: The Editor

...
...

This report explains **HTTP Strict Transport Security (HSTS)** (RFC 6797), its origins from ForceHTTPS, how it enforces HTTPS-only access via headers and preload lists, and why it matters for defending against passive/active network attacks and downgrade techniques like **sslstrip**. It details required header directives, deployment considerations (includeSubDomains, preload), and the first-visit weakness mitigated by preloading, while noting how attackers can still perform MitM if sites are misconfigured or not preloaded.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.