Reply to post: Re: Not the best of articles.

El Reg assesses crypto of UK banks: Who gets to wear the dunce cap?

Alex Brett

Re: Not the best of articles.

Yes - while /you/ as the site admin might not be running a site on port 80, the person who attacks the end user can, and there browser will happily connect to it, whereas with HSTS the browser will always go to the HTTPS site and thus as well as MITMing the connection, you have to somehow get the browser to trust the certificate you present as well...

