Malware
HSTS
Also called HTTP Strict Transport Security.
HSTS is a response header that tells the browser to use HTTPS only for this domain for a set time. After the first visit, the browser upgrades every request itself and refuses to proceed past a certificate error.
How it is measured
Check the `Strict-Transport-Security` header in responses from the site. A typical value is `max-age=31536000; includeSubDomains`. The number is seconds the browser remembers the rule. A preload flag asks for inclusion in the list built into browsers.
Fetch with `curl -I https://example.com` and read the header. Also test `http://` and confirm it redirects to HTTPS, since HSTS is ignored over plain HTTP.
Worked example
A bookstore enables HTTPS in January but forgets HSTS. A visitor on cafe Wi-Fi types the domain without a scheme, and the first request goes out as HTTP. An attacker on the network answers it and proxies the session, so the visitor sees a lookalike without a warning.
After the store sends `max-age=31536000; includeSubDomains`, a returning visitor's browser goes straight to HTTPS and the interception attempt fails.
How it differs
HSTS forces HTTPS on the browser side. A TLS certificate is what makes HTTPS possible in the first place. A valid certificate without HSTS still permits a first plain HTTP request; HSTS with a broken certificate locks users out with no bypass. Mixed content is a separate failure, where an HTTPS page pulls an HTTP script or image.
Common errors
Setting a one-year max-age before testing every subdomain. Adding `includeSubDomains` with a legacy host still on HTTP. Submitting to the preload list lightly, since removal is slow. Sending the header over HTTP, where it is ignored. Letting the certificate expire on an HSTS site.
In practice
Start with a short max-age, such as five minutes, then raise it to a week and then a year as subdomains are confirmed. Check every subdomain serves HTTPS. Only add preload when you are sure you will never need HTTP again.