Secure by default: How ‘HSTS-Enforced’ could finally close the web’s oldest backdoor
Guest Post: The current web still relies on a legacy assumption that website should be accessible over unencrypted HTTP unless it explicitly signals otherwise. HSTS-Enforced builds on top of HSTS by inverting its security model.