HSTS
HTTP Strict Transport Security
In short
HSTS is a security header that tells browsers to connect to a site only over HTTPS for a set period, blocking insecure HTTP connections and downgrade attacks.
What is HSTS?
HTTP Strict Transport Security, or HSTS, is a response header a website sends to say: from now on, only talk to me over HTTPS. After a browser sees the Strict-Transport-Security header, it automatically upgrades every future http:// link and typed address for that domain to https:// before any request leaves the machine. It also stops users from clicking through certificate warnings on that site.
The header has a max-age value in seconds, often one or two years, that tells the browser how long to remember the rule, and an optional includeSubDomains flag that applies it to every subdomain. The browser only accepts the header when it arrives over a valid HTTPS connection. Because the very first visit could still happen over plain HTTP, browsers also ship a built-in HSTS preload list: sites that meet the requirements and add the preload flag can be included, so browsers use HTTPS for them even on the first visit.
Without HSTS, a user who types example.com usually makes a plain HTTP request first and is then redirected to HTTPS, and an attacker on the same public Wi-Fi can intercept that first request and keep the victim on an unencrypted connection, a technique called SSL stripping. HSTS removes that window. It is like a standing rule at a bank that large withdrawals are only handled at the secure counter: once the rule is on file, nobody can talk a teller into using the unlocked side door.
HSTS is often confused with HTTPS itself or with an HTTP-to-HTTPS redirect. HTTPS provides the encryption, and a redirect sends users to it after an insecure request has already been made, while HSTS makes the browser refuse to use HTTP at all for that site. Be careful with includeSubDomains and preloading, because every subdomain must then support HTTPS, and removing a site from the preload list takes months.
Key takeaways
- HSTS tells browsers to use only HTTPS for a site for a set period.
- It is sent in the
Strict-Transport-Securityresponse header over HTTPS. - It blocks SSL stripping and other downgrade attacks after the first visit.
- The preload list protects even the first visit for sites that opt in.
- Test with a short
max-agebefore committing to long values and preloading.
Example
# Check whether a site sends the HSTS header
curl -sI https://example.com | grep -i strict-transport-security
# A typical strong policy: two years, all subdomains, eligible for preloading
# Strict-Transport-Security: max-age=63072000; includeSubDomains; preload
# Start with a short max-age (5 minutes) while testing
# Strict-Transport-Security: max-age=300Readers ask
Is an HTTP to HTTPS redirect enough without HSTS?
No. The redirect only happens after the browser has already sent an insecure request, which an attacker on the network can intercept. HSTS makes the browser skip plain HTTP entirely on later visits.
What is the HSTS preload list?
It is a list of domains built into major browsers that are always loaded over HTTPS, even on the first visit. A site can apply by sending an HSTS header with a long max-age, includeSubDomains, and preload, and by serving HTTPS on all its subdomains.
What happens if my certificate expires on an HSTS site?
Browsers block the site with an error that users cannot click through, because HSTS forbids bypassing certificate warnings. Automate certificate renewal before enabling a long max-age.
See also
- HTTPSSecurity, p. 17HTTPS is the secure version of HTTP that encrypts traffic between a browser and a website with TLS, protecting data from eavesdropping and tampering.
- TLSSecurity, p. 45TLS is the cryptographic protocol that encrypts data sent over a network and verifies the server's identity, securing HTTPS, email, and many other connections.
- Man-in-the-Middle AttackSecurity, p. 21A man-in-the-middle attack happens when an attacker secretly relays, and may alter, messages between two parties who think they are talking directly.
- Certificate AuthoritySecurity, p. 5A certificate authority is a trusted organization that issues digital certificates confirming a public key belongs to a specific website, company, or person.
- Content Security PolicySecurity, p. 7A Content Security Policy is an HTTP response header that tells the browser which scripts, styles, and other resources a page may load, blocking injected code.
Spotted a mistake or something missing on this page?Suggest an edit