-
@troyhunt @lespacedunmatin HSTS, but also HPKP. And DNSSec with TLSA.
-
@troyhunt @lespacedunmatin With HSTS only, you have no protection. Anybody can ask for a valid HTTPS certificate with LetsEncrypt as soon as he controls the DNS.
-
@troyhunt @lespacedunmatin You need DNSSec too to protect against such DNS hijack (with TLSA for cert protection). And HPKP to detect certificate change.
aeris22’s Twitter Archive—№ 54,940