Later archive addition
Breaking Out HSTS (and HPKP) on Firefox, IE/Edge and (Possibly) Chrome
Firefox, IE/Edge and Chrome store HSTS and HPKP state in ways an attacker can remotely overwrite, so a site that should be locked to HTTPS can be pushed back to plaintext. A sniffing or man-in-the-middle attacker on the same network then reads credentials from sites that had enforced HTTPS.
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of its author, first published at the original source. Preserved copies are kept so the citation survives its host.