The State of HSTS Deployment: A Survey and Common Pitfalls
Lucas Garron, Andrew Bortz, Dan Boneh · 2014
HSTS (HTTP Strict Transport Security) has gained signicant browser and server adoption since reaching IETF proposed status. However, there are several important deployment challenges. A scan of top websites reveals that many HSTS sites have not properly congured the HSTS header, which still leaves them open to some attacks HSTS is meant to solve. We survey the current state of deployment and describe common mistakes and diculties with HSTS conguration. We conclude with approaches for properly deploying HSTS as eectively as possible.