disabling HSTS
disabling HSTS
Posted Apr 18, 2017 8:54 UTC (Tue) by linuxrocks123 (subscriber, #34648)In reply to: disabling HSTS by tialaramex
Parent article: Tor exit node operator arrested in Russia (TorServers.net blog)
I wouldn't necessarily trust the general population to know when and when not to override SSL errors, but I would certainly trust just about everyone on this site. I'd trust most of SoylentNews and Slashdot, even. Not that it matters, because, even if I didn't, people at our level will find a way. Ffs, the comment we're replying to is someone talking about how to type raw HTTP GET commands into openssl so you can save the HTML to a file and then point the browser at that file ... to override the SSL error. And thanks, btw, I learned something new from that, but it's also absurd that some browsers reduce us to having to do that.
You want to stop the clueless from overriding SSL errors for HSTS sites, make it a hidden option in about:config and be done with it. Don't get in the way of the significant population of people who know what they're doing.
