Comment on Local pop radio station is using its metadata to spread anti Biden propaganda

<- View Parent
azertyfun@sh.itjust.works ⁨10⁩ ⁨months⁩ ago

HSTS + HTTPS redirect is the answer. It’s industry standard for a reason: it’s just as safe as pure HTTPS since you can’t get anything other than a redirect over HTTP, and HSTS protects your users from future attempted MITM attacks. The MDN page for HSTS explains it all very clearly.

Any other implementation is an immediate audit fail in my experience.

There’s no tangible security benefit to fully disabling port 80, and if anything depending on the service it may just drive users away to shadier alternatives.

source
Sort:hotnewtop