Skip to content

Comment on Websites Must Use HSTS in Order to Be Secureparent

Comments

I believe that Firefox is still generating its HSTS preload list from Chromium's - a few months ago I got a site added to Chromium's HSTS list and a few weeks later it showed up in Firefox. I couldn't even figure out how to submit directly to Firefox.

I agree that a global registry would be better, but it should probably be updated using the browser's normal update channel, to avoid re-inventing the wheel. (And DNSSEC has way too many issues.) It's true that ties the list to specific releases, but since browsers have good, and frequent, auto-updating, I think that's OK.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.