HSTS tells browsers to ignore the HTTP response other than the redirect-to-HTTPS, and then the HTTPS served HSTS locks the browser in for the period the HSTS header states.
1
Then again, getting on the preload list is fairly easy, if slow.
Jul 24, 2018 ยท 9:12 AM UTC

