Yes, but you'd have to serve that over HTTPS. And even then, how do you know that all the caches that have the older, longer expiration time have revisited and updated their cache? You won't, really, until that many seconds have pass.
Right, my point was just that there is a specified way for the server to tell the client not to use HSTS any more. Of course, the caveats you mention mean that to be certain, you would need to wait.
Comments
Yes, but you'd have to serve that over HTTPS. And even then, how do you know that all the caches that have the older, longer expiration time have revisited and updated their cache? You won't, really, until that many seconds have pass.
Right, my point was just that there is a specified way for the server to tell the client not to use HSTS any more. Of course, the caveats you mention mean that to be certain, you would need to wait.