Reply to post:

El Reg assesses crypto of UK banks: Who gets to wear the dunce cap?


Is HSTS really necessary if the site is not even listening for HTTP traffic?

If you do your HTTP -> HTTPS redirect on a separate site then there's no way the main site can ever respond to anything on HTTP.

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon

Biting the hand that feeds IT © 1998–2019