you are viewing a single comment's thread
view the rest of the comments
[–] 5 points 9 months ago (3 children)
  • [–] 1 point 9 months ago (2 children)

    Only if the site they’re visiting isn’t using HSTS, but it’s possible

  • source
  • parent
  • hideshow 2 child comments
  • [–] 3 points 9 months ago (1 child)

    I don't think this is correct. HSTS only prevents downgrading.

  • source
  • parent
  • hideshow 1 child comment
  • [–] 2 points 9 months ago

    HSTS says it must be encrypted but a proxy will create two connections and look at it clear in the middle. On the other hand cert pinning says it must be a specific cert that breaks the site if decryption is used. Apple is big on doing that for a lot of their site and apps.

  • source
  • parent