Skip to content

Archive

HTTPS

13 articles
Cybersecurity 24 Sep 2026 5 min read

HSTS Pins HTTP Origins to TLS After First Secure Contact

HTTPS protects a connection only after the client has selected HTTPS and completed TLS. A user who enters a bare hostname, follows an http:// bookmark, or receives an HTTP link can still begin on cleartext HTTP before a server redirects the request. HTTP Strict Transport Security (HSTS), defined in RFC 6797, moves that redirect decision into the user agent after the origin has established a policy over a secure connection.

Cybersecurity 24 Sep 2026 5 min read

HSTS Keeps HTTPS Downgrades Out of Later Connections

TLS protects an HTTPS connection only after the client has chosen HTTPS and completed the TLS handshake. That leaves a separate problem at the scheme boundary. A user can enter a bare hostname, follow an old http:// link, or reach a redirect that starts in cleartext. An attacker able to interfere with that first HTTP exchange can try to keep the browser away from HTTPS. HTTP Strict Transport Security (HSTS), defined by RFC 6797, moves that decision into the user agent. After a host sends a valid Strict-Transport-Security header over a secure connection, a conforming user agent records the policy. During its lifetime, later attempts to contact that host with HTTP are converted to HTTPS before an HTTP request is sent.

Cybersecurity 23 Sep 2026 6 min read

HTTP Strict Transport Security Pins HTTPS for Future Visits

HTTP Strict Transport Security Pins HTTPS for Future Visits TLS protects an HTTP connection only after the client is using HTTPS. A user who enters a bare hostname, follows an old http:// link, or reaches a redirecting HTTP endpoint can still begin with an unencrypted request. HTTP Strict Transport Security (HSTS) gives a supporting browser a persistent rule for that host. After receiving a valid Strict-Transport-Security header over HTTPS, the browser records the policy and rewrites later HTTP navigation to HTTPS while the policy remains active.

Cybersecurity 22 Sep 2026 5 min read

HSTS Pins HTTPS Policy to Hostnames

HSTS Pins HTTPS Policy to Hostnames HTTPS protects an HTTP exchange after a secure connection has been established and authenticated. A separate problem appears before that point: a user can enter a bare hostname, follow an http:// link, or reach a redirecting HTTP endpoint before the browser has any transport policy for the site. HTTP Strict Transport Security (HSTS) addresses that transition. An HTTPS server sends a Strict-Transport-Security response header, and a conforming user agent records a policy for the host. While that policy remains active, matching HTTP requests are converted to HTTPS before an insecure network request is sent.

Cybersecurity 22 Sep 2026 5 min read

HSTS Enforces HTTPS After a Secure Origin Establishes Policy

HSTS Enforces HTTPS After a Secure Origin Establishes Policy HTTPS protects an HTTP exchange only after a secure connection is in use. A user can still type a bare hostname, follow an http:// link, or encounter an application that redirects HTTP to HTTPS. That initial HTTP request exists before an ordinary redirect can move the browser onto TLS. HTTP Strict Transport Security (HSTS) moves the redirect decision into the user agent. A host sends the Strict-Transport-Security response header over HTTPS. Once the browser accepts that policy, later attempts to access the covered host with HTTP are rewritten to HTTPS before an insecure HTTP request is sent.

Cybersecurity 21 Sep 2026 5 min read

HSTS Pins HTTPS Policy in the Browser

HSTS Pins HTTPS Policy in the Browser An HTTPS redirect does useful work only after an HTTP request reaches the server. That first cleartext request remains a weak point: a network attacker able to alter traffic can interfere before the browser receives the redirect. HTTP Strict Transport Security, or HSTS, moves part of that decision into the browser. After receiving a valid Strict-Transport-Security header over HTTPS, a conforming user agent records a policy for the host. During the policy lifetime, later HTTP navigation to that host is rewritten to HTTPS before an HTTP connection is made.

Cybersecurity 21 Sep 2026 5 min read

HSTS Enforces HTTPS After a Host Policy Is Known

HSTS Enforces HTTPS After a Host Policy Is Known A redirect from HTTP to HTTPS moves a request onto TLS, but the first HTTP request still exists. If a browser starts with http://example.com, it can contact the HTTP endpoint before it receives the redirect. A network attacker positioned on that path can interfere before the browser reaches TLS. HTTP Strict Transport Security (HSTS), standardized in RFC 6797, changes later navigation behavior. A conforming user agent that receives a valid Strict-Transport-Security response over secure transport records an HTTPS-only policy for the host. While that policy remains active, an HTTP URL for the host is rewritten to HTTPS before an insecure request is sent.

Cybersecurity 16 Sep 2026 8 min read

HSTS Caches Transport Policy Beyond the Response That Declared It

HSTS Caches Transport Policy Beyond the Response That Declared It A site can redirect every plain-HTTP request to HTTPS and still expose the first request of a fresh browser session to an active network attacker. The redirect is delivered only after the browser has already contacted the HTTP endpoint. HTTP Strict Transport Security changes that sequence by moving a transport decision into browser state. After a valid Strict-Transport-Security response arrives over secure transport, a conforming browser records policy for the host. Later attempts to reach that host through HTTP are rewritten toward HTTPS before an insecure request is sent. The control therefore persists beyond the response that declared it.

Cybersecurity 15 Sep 2026 6 min read

HSTS Turns HTTPS Preference Into Browser Policy

HSTS Turns HTTPS Preference Into Browser Policy An HTTPS site can configure perfect TLS and still expose a weaker first contact. If a person types a bare hostname, follows an old http:// bookmark, or opens an insecure link, the browser may send an HTTP request before the server redirects it to HTTPS. An active network attacker gets an opportunity before the protected connection exists. HTTP Strict Transport Security, or HSTS, moves that redirect decision into the browser. After a browser receives a valid HSTS policy over HTTPS, it records that the host must be contacted securely for the policy lifetime. Later HTTP navigation to that host is upgraded locally rather than sent across the network as cleartext HTTP.

Cybersecurity 14 Sep 2026 7 min read

HSTS Moves HTTPS Policy Into the User Agent

HSTS Moves HTTPS Policy Into the User Agent An HTTPS site can have a valid certificate, modern TLS settings, and a permanent redirect from HTTP, yet still expose a narrow transport-security gap before that redirect is received. If a browser begins with a plain HTTP request, the server has no opportunity to protect that request until it arrives. An attacker able to alter traffic on that path can interfere before TLS is established.

Tech 14 Sep 2026 6 min read

DNS over HTTPS Encrypts Resolver Queries

Opening a website usually starts before the browser sends an HTTP request. The device first needs an IP address for the hostname, and DNS commonly provides that mapping. Traditional DNS traffic can expose those queries to systems along the network path because classic resolver exchanges are not encrypted by default. DNS over HTTPS, usually shortened to DoH, changes the transport. It sends DNS messages through HTTPS, so the request and response receive the confidentiality and integrity protection of the HTTPS connection between the client and the selected resolver.

Cybersecurity 12 Sep 2026 7 min read

Enforce HTTPS with HSTS

TLS protects an HTTP connection after the browser starts HTTPS. A plain HTTP request sent before a redirect is different: it has no TLS protection, so a network attacker can alter the response and prevent the redirect from reaching the browser. HTTP Strict Transport Security (HSTS) gives a site a browser-enforced transport rule. After receiving a valid HSTS policy over HTTPS, a supporting browser remembers that the host must use HTTPS for a defined period. Future HTTP navigation attempts are upgraded locally before an insecure request is sent.

Cybersecurity 11 Sep 2026 8 min read

Enforce HTTPS with HTTP Strict Transport Security

TLS protects an HTTP connection after the browser has chosen HTTPS and completed certificate validation. A separate problem exists before that protected connection begins: a user can type a bare hostname, follow an old HTTP link, or reach a page that redirects from HTTP to HTTPS. HTTP Strict Transport Security, usually called HSTS, lets a site tell supporting browsers to treat future connections to that host as HTTPS-only. The browser stores the policy for a defined period. While the policy is active, an HTTP navigation is upgraded locally before an insecure HTTP request is sent.