- Servers can send HTTP headers to provide the client with additional metadata around the response. Besides sending the content that the client requested, servers are then allowed to specify how a particular resource should be read, cached or secured.
- They have been implemented by browsers in order to make it harder for attackers to take advantage of vulnerabilities.
- HTTP Strict Transport Security.
- A simple
Strict-Transport-Security: max-age=3600will tell the browser that for the next hour (3600 seconds) it should not interact with the applications with insecure protocols. - To Check: https://hstspreload.org/?domain=facebook.com
- Prevents: MITM, Eavesdropping attack