Breaking News

Arctic announces Senza AI 370 Under Desk PC for AI Applications CORSAIR Announces the Airflow-focused 3200D Mid Tower for Ambitious DIY PC Builds Silicon Power Launches Enterprise-Grade DDR5 RDIMM to Accelerate AI Workloads World Backup Day 2026: A Backup Doesn’t Always Need to be in the Cloud Sharkoon announces S100 ARGB AIO Cooler

logo

  • Share Us
    • Facebook
    • Twitter
  • Home
  • Home
  • News
  • Reviews
  • Essays
  • Forum
  • Legacy
  • About
    • Submit News

    • Contact Us
    • Privacy

    • Promotion
    • Advertise

    • RSS Feed
    • Site Map

Search form

Firefox Enforces Secure HSTS Connections For Selected Domains

Firefox Enforces Secure HSTS Connections For Selected Domains

Enterprise & IT Nov 2,2012 0

Mozilla introduced a pre-loaded list of domains for Firefox that only can be connected to securely in order to help protect the privacy and security of users. HSTS (HTTP Strict Transport Security) is a mechanism by which a server can indicate that the browser must use a secure connection when communicating with it. It can be an effective tool for protecting the privacy and security of users and their data. However, when connecting to an HSTS host for the first time, the browser won't know whether or not to use a secure connection, because it has never received an HSTS header from that host. Consequently, an active network attacker could prevent the browser from ever connecting securely.

To mitigate this attack, Mozilla has added to Firefox a list of hosts that want HSTS enforced by default. When a user connects to one of these hosts for the first time, the browser will know that it must use a secure connection. If a network attacker prevents secure connections to the server, the browser will not attempt to connect over an insecure protocol, thus maintaining the user?s security.

The "preload list" has been seeded with entries from Chrome's list of a similar function. To build the preload list, a request is sent to every host with 'mode: "force-https"' on Chrome's list. Only if a host responds with a valid HSTS header with an appropriately large max-age value do Mozilla includes it in its list. Mozilla also see if the includeSubdomains value for the entry on Chrome?s list is the same as what they receive in the response header.

Google's Chrome forces a secure connection for all google.com subdomains but also added forced HTTPS connections for sites that have requested it.

The feature is currently only present in Firefox Beta.

Tags: Firefox
Previous Post
Facebook To Educate New Users Over Privacy
Next Post
Apple's Updated Samsung Statement Still Not an Apology

Related Posts

  • Latest Firefox Helps You Keep Your Passwords Safe

  • Latest Firefox Updates Address Bar For Easier Search

  • Scroll Partners With Firefox to Build a Better Internet

  • Firefox Brings DNS Over HTTPS by Default for US Users

  • Mozilla Patches Critical Firefox Vulnerability

  • Firefox Announces New Partner in Delivering Private DNS Services

  • Firefox 71 Supports Picture-in-Picture

  • Mozilla Removes Avast Extensions From Their Add-on Store on Spyware Issues

Latest News

Arctic announces Senza AI 370 Under Desk PC for AI Applications
Consumer Electronics

Arctic announces Senza AI 370 Under Desk PC for AI Applications

CORSAIR Announces the Airflow-focused 3200D Mid Tower for Ambitious DIY PC Builds
Cooling Systems

CORSAIR Announces the Airflow-focused 3200D Mid Tower for Ambitious DIY PC Builds

Silicon Power Launches Enterprise-Grade DDR5 RDIMM to Accelerate AI Workloads
Enterprise & IT

Silicon Power Launches Enterprise-Grade DDR5 RDIMM to Accelerate AI Workloads

World Backup Day 2026: A Backup Doesn’t Always Need to be in the Cloud
Enterprise & IT

World Backup Day 2026: A Backup Doesn’t Always Need to be in the Cloud

Sharkoon announces S100 ARGB AIO Cooler
Cooling Systems

Sharkoon announces S100 ARGB AIO Cooler

Popular Reviews

be quiet! Dark Mount Keyboard

be quiet! Dark Mount Keyboard

Terramaster F8-SSD

Terramaster F8-SSD

be quiet! Light Mount Keyboard

be quiet! Light Mount Keyboard

Akaso 360 Action camera

Akaso 360 Action camera

Dragon Touch Digital Calendar

Dragon Touch Digital Calendar

be quiet! Pure Loop 3 280mm

be quiet! Pure Loop 3 280mm

Noctua NF-A12x25 G2 fans

Noctua NF-A12x25 G2 fans

Arctic Liquid Freezer III 360 Pro Argb

Arctic Liquid Freezer III 360 Pro Argb

Main menu

  • Home
  • News
  • Reviews
  • Essays
  • Forum
  • Legacy
  • About
    • Submit News

    • Contact Us
    • Privacy

    • Promotion
    • Advertise

    • RSS Feed
    • Site Map
  • About
  • Privacy
  • Contact Us
  • Promotional Opportunities @ CdrInfo.com
  • Advertise on out site
  • Submit your News to our site
  • RSS Feed