Replying to @pwaring
Leeds do ๐Ÿ˜‰
HSTS tells browsers to ignore the HTTP response other than the redirect-to-HTTPS, and then the HTTPS served HSTS locks the browser in for the period the HSTS header states.
1
So yes, unless you're in the preload list, it won't prevent a MITM doing an HTTP-only thing, but the moment *any* resource gets loaded from the HTTPS real site, the browser is "fixed"

Jul 24, 2018 ยท 9:10 AM UTC

1