So yes, unless you're in the preload list, it won't prevent a MITM doing an HTTP-only thing, but the moment *any* resource gets loaded from the HTTPS real site, the browser is "fixed"
Jul 24, 2018 ยท 9:10 AM UTC
1
Jul 24, 2018 ยท 9:10 AM UTC