Hacked in a public space? Thanks, HTTPS

Tom Chiverton 1

I thought most popular sites were handing out HSTS headers, so browsers will refuse to connect over plain text ?

