Breaking News

KIOXIA Introduces EXCERIA BASIC SSD Series for Affordable PCIe 4.0 Upgrades First look at PlayStation’s 27” Gaming Monitor New Transcend CFexpress 830 Type B Targets 8K RAW, High-Speed Shooting, and Pro Video Production Firewalla Launches MSP 2.9: Introducing FireAI Search, AP7 Wi-Fi Management, Enhanced User Support, Mobile App Access Control Elgato Launches Retail-Exclusive, Discord-Edition Stream Deck Mini

logo

  • Share Us
    • Facebook
    • Twitter
  • Home
  • Home
  • News
  • Reviews
  • Essays
  • Forum
  • Legacy
  • About
    • Submit News

    • Contact Us
    • Privacy

    • Promotion
    • Advertise

    • RSS Feed
    • Site Map

Search form

Internet Explorer To Support HTTP Strict Transport Security Protocol

Internet Explorer To Support HTTP Strict Transport Security Protocol

Enterprise & IT Feb 16,2015 0

Microsoft today announced support for HTTP Strict Transport Security (HSTS) in Internet Explorer. This change can be previewed using Internet Explorer in the Windows 10 Technical Preview, and will come to Microsoft's new browser - Project Spartan - in a later update.

The HSTS policy protects against variants of man-in-the-middle attacks that can strip TLS out of communications with a server, leaving the user vulnerable. For example, a user may initially connect to a non-encrypted version of a website before being redirected to a secure connection. An attacker exploiting the non-encrypted connection could redirect the user to a malicious site. HSTS mitigates this attack vector by allowing sites to specify that the browser should always use a secure connection to the server.

With HSTS, websites can register to be hardcoded by IE and other browsers to redirect HTTP traffic to HTTPS. Communications with these websites from the initial connection are automatically upgraded to be secure. Like other browsers which have implemented this feature, Internet Explorer's preload list is based on the Chromium HSTS preload list.

Sites not on the preload list can enable HSTS via the Strict-Transport-Security HTTP header. After an initial HTTPS connection from the client containing the HSTS header, any subsequent HTTP connections are redirected by the browser to be secured via HTTPS.

There are two important changes that impact users on sites using HSTS. First, when there is a certification error with a HSTS server, the user will not be able to click through and ignore the certificate error; they must abort their connection. Second, mixed content is not supported on servers supporting HSTS; all the content must be secure.

Tags: Microsoft
Previous Post
Spying Program Was Stored Within Popular Hard Disk Drives
Next Post
New Apple iWork Apps Run On PCs Too

Related Posts

  • Snapdragon X Series is the Exclusive Platform to Power the Next Generation of Windows PCs with Copilot+ Today

  • Activision Blizzard King to Team Xbox

  • NVIDIA Studio Lineup Adds RTX-Powered Microsoft Surface Laptop Studio 2

  • Samsung and Microsoft Unveil First On-Device Attestation Solution for Enterprise

  • Introducing Xbox Game Pass Core, Coming This September

  • Announcing the next wave of AI innovation with Microsoft Bing and Edge

  • Microsoft Announces Security Copilot AI

  • Microsoft breaks new ground in healthcare with the next evolution of AI

Latest News

KIOXIA Introduces EXCERIA BASIC SSD Series for Affordable PCIe 4.0 Upgrades
PC components

KIOXIA Introduces EXCERIA BASIC SSD Series for Affordable PCIe 4.0 Upgrades

First look at PlayStation’s 27” Gaming Monitor
Gaming

First look at PlayStation’s 27” Gaming Monitor

New Transcend CFexpress 830 Type B Targets 8K RAW, High-Speed Shooting, and Pro Video Production
Cameras

New Transcend CFexpress 830 Type B Targets 8K RAW, High-Speed Shooting, and Pro Video Production

Firewalla Launches MSP 2.9: Introducing FireAI Search, AP7 Wi-Fi Management, Enhanced User Support, Mobile App Access Control
Enterprise & IT

Firewalla Launches MSP 2.9: Introducing FireAI Search, AP7 Wi-Fi Management, Enhanced User Support, Mobile App Access Control

Elgato Launches Retail-Exclusive, Discord-Edition Stream Deck Mini
Consumer Electronics

Elgato Launches Retail-Exclusive, Discord-Edition Stream Deck Mini

Popular Reviews

be quiet! Dark Mount Keyboard

be quiet! Dark Mount Keyboard

Terramaster F8-SSD

Terramaster F8-SSD

be quiet! Light Mount Keyboard

be quiet! Light Mount Keyboard

Soundpeats Pop Clip

Soundpeats Pop Clip

Akaso 360 Action camera

Akaso 360 Action camera

Dragon Touch Digital Calendar

Dragon Touch Digital Calendar

Noctua NF-A12x25 G2 fans

Noctua NF-A12x25 G2 fans

be quiet! Pure Loop 3 280mm

be quiet! Pure Loop 3 280mm

Main menu

  • Home
  • News
  • Reviews
  • Essays
  • Forum
  • Legacy
  • About
    • Submit News

    • Contact Us
    • Privacy

    • Promotion
    • Advertise

    • RSS Feed
    • Site Map
  • About
  • Privacy
  • Contact Us
  • Promotional Opportunities @ CdrInfo.com
  • Advertise on out site
  • Submit your News to our site
  • RSS Feed