{"id":5128,"date":"2017-10-02T11:30:03","date_gmt":"2017-10-02T15:30:03","guid":{"rendered":"https:\/\/www.thesslstore.com\/blog\/?p=5128"},"modified":"2020-08-24T15:41:30","modified_gmt":"2020-08-24T19:41:30","slug":"what-is-hypertext-strict-transport-security-hsts","status":"publish","type":"post","link":"https:\/\/www.thesslstore.com\/blog\/what-is-hypertext-strict-transport-security-hsts\/","title":{"rendered":"What is HTTP Strict Transport Security (HSTS)?"},"content":{"rendered":"<h2>HTTP Strict Transport Security forces browsers to make secure HTTPS connections with websites.<\/h2>\n<p>HTTP Strict Transport Security has been in the news a little bit lately thanks to <a href=\"https:\/\/www.thesslstore.com\/blog\/google-forcing-https-connections-45-tlds-hsts\/\" rel=\"nofollow\">Google&#8217;s decision to add 45 TLDs to the HSTS pre-load list<\/a>. So, given the recent attention paid to it, we decided we would give you a rundown of HSTS is and why it&#8217;s an effective complement to your current SSL implementation.<\/p>\n<p>Let&#8217;s Hash it Out&#8230;<span id=\"newline\"><\/span><\/p>\n<h2>What is HSTS?<\/h2>\n<p>HTTP Strict Transport Security is a web security policy sent via header, that forces browsers to make secure HTTPS connections when they visit a specified website. This prevents cookie hijacking and protocol downgrade attacks. This is accomplished by setting a Strict-Transport-Security parameter that forces all connections to be made securely and disregards and scripts that attempt to load assets over unsecure\u00a0HTTP. The header sets a period of time that the paramater applies for.<\/p>\n<p>HSTS is an IETF standards track protocol. It is specified in <a href=\"https:\/\/tools.ietf.org\/html\/rfc6797\" rel=\"nofollow\">RFC 6797<\/a> after being approved exactly five years ago today, October 2nd, 2012.<\/p>\n<span style=\"--tl-form-height-m:150.25px;--tl-form-height-t:121.4583px;--tl-form-height-d:121.4583px;\" class=\"tl-placeholder-f-type-shortcode_12753 tl-preload-form\"><span><\/span><\/span>\n<h2>There is one security risk inherent with HSTS<\/h2>\n<p>There&#8217;s one major risk that presents itself with HSTS. Because the STS parameter is communicated in the form of a header, there is still a small window of opportunity to attack during the very first connection &#8211; before a browser has had an opportunity to receive the header. It&#8217;s a rather narrow attack vector, but with the right tools a hacker could strip down your SSL encryption and steal data or even attempt to phish you.<\/p>\n<p>Again, it&#8217;s a small window, but it can be exploited and frankly, any risk you can mitigate should definitely be mitigated. So there is a solution in the form of the HSTS preload list.<\/p>\n<h2>What is the HSTS Preload list?<\/h2>\n<p>The HSTS Preload list a set of pre-loaded websites that employ HSTS. This effectively closes the window for a first connection protocol downgrade or cookie hijacking. When a web browser arrives at a website on the HSTS preload list for the first time it already knows to only make secure connections.<\/p>\n<p>The only problem with the HSTS preload list is that it can take a while to get on. You&#8217;re at the mercy of the browsers as to when they update before you&#8217;ll be included on the list itself. With some browsers that&#8217;s nearly on a monthy\u00a0basis &#8211; so the wait will only be a few weeks &#8211; but for others, it can be months. That&#8217;s why Google&#8217;s decision to register all of its TLDs on the list is so powerful. Now any website with those TLDs &#8211; that is secured with an SSL certificate &#8211; is already on the list by default.<\/p>\n<p>Look for plenty of other domain registrars to follow suit in the coming months.<\/p>\n<h2>Should I implement HSTS on my website?<\/h2>\n<p>Yes. We definitely recommend employing HSTS. Even with an SSL certificate, there are still ways to exploit a site. Especially one that uses 301 redirects to send traffic to the HTTPS versions of its original HTTP pages. Not having HSTS is like putting a nice big padlock on the front door of your website, but accidentally leaving a window unlocked. There&#8217;s still a way to get in, you just have to be a little more sophisticated to find it.<\/p>\n<p>So yes, we recommend implementing HSTS. Not only HSTS, but we recommend writing the header with the &#8220;includeSubDomains&#8221; and &#8220;preload&#8221; prompts included as well.<\/p>\n<p>Here is an example of a good HSTS header:<\/p>\n<p><code>Strict-Transport-Security: max-age=31536000; includeSubDomains; preload<\/code><\/p>\n<h2>What to consider before implementing HSTS<\/h2>\n<p>There are a few things worth noting about HSTS before you go ahead and add the appropriate header:<\/p>\n<ul>\n<li>You must have an SSL certificate installed on your website already<\/li>\n<li>If you have sub-domains you will need to use a wildcard to protect them<\/li>\n<li>You must use 301 redirects to reroute all HTTP pages to HTTPS ones<\/li>\n<li>Google says best practice is two set a max age of two years<\/li>\n<li>SubDomain and preload headers must be included<\/li>\n<\/ul>\n<p><em><strong>Important Note:<\/strong><\/em> Just adding &#8220;preload&#8221; will not get you on the HSTS preload list. <a href=\"https:\/\/www.google.com\/url?sa=t&amp;rct=j&amp;q=&amp;esrc=s&amp;source=web&amp;cd=1&amp;cad=rja&amp;uact=8&amp;ved=0ahUKEwjQurSKnNLWAhVI5mMKHcT4BhsQFggoMAA&amp;url=https%3A%2F%2Fhstspreload.org%2F&amp;usg=AOvVaw3zi-S9jfoqN_1yZ0oKDmbJ\" rel=\"nofollow\">You will still need to follow up yourself by going here<\/a>.<\/p>\n<h2>HSTS Header for Microsoft IIS Servers<\/h2>\n<p><code><span class=\"gs_59cd26039893c\">protected void\u00a0Application_BeginRequest(Object sender,\u00a0EventArgs\u00a0e) { switch (Request.Url.Scheme) { case \"https\":\u00a0Response.AddHeader(\"Strict-Transport-Security\", \"max-age=31536000;\u00a0includeSubDomains; preload\"); break; case \"http\":\u00a0var\u00a0path = \"https:\/\/\" +\u00a0Request.Url.Host\u00a0+\u00a0Request.Url.PathAndQuery;\u00a0Response.Status\u00a0= \"301 Moved Permanently\";\u00a0Response.AddHeader(\"Location\", path); break; } }<\/span><\/code><\/p>\n<h2>HSTS Header for Nginx<\/h2>\n<p><code><span class=\"gs_59cd2603988f6\">add_header\u00a0Strict-Transport-Security 'max-age=300;\u00a0includeSubDomains; preload; always;'<\/span><\/code><\/p>\n<h2>HSTS Header for lighttpd<\/h2>\n<p><code><span class=\"gs_59cd2603988b1\">server.modules\u00a0+= ( \"mod_setenv\" ) $HTTP[\"scheme\"] == \"https\" {\u00a0setenv.add-response-header = (\"Strict-Transport-Security\" =&gt; \"max-age=300;\u00a0includeSubDomains; preload\") }<\/span><\/code><\/p>\n<h2>HSTS Header for Apache Web Server<\/h2>\n<p><code><span class=\"gs_59cd26039886b\"># Use HTTP Strict Transport Security to force client to use secure connections only Header always set Strict-Transport-Security \"max-age=300;\u00a0includeSubDomains;\u00a0preload\"<\/span><\/code><\/p>\n<h2>How to Sign Up for the HSTS Preload List<\/h2>\n<p>To submit your website for the HSTS preload list, you must first satisfy these official requirements:<\/p>\n<ol>\n<li>\n<blockquote><p>Serve a valid\u00a0<b>certificate<\/b>.<\/p><\/blockquote>\n<\/li>\n<li>\n<blockquote><p><b>Redirect<\/b>\u00a0from HTTP to HTTPS on the same host, if you are listening on port 80.<\/p><\/blockquote>\n<\/li>\n<li>\n<blockquote><p>Serve all\u00a0<b>subdomains<\/b>\u00a0over HTTPS.<\/p>\n<ul>\n<li>In particular, you must support HTTPS for the\u00a0<tt>www<\/tt>\u00a0subdomain if a DNS record for that subdomain exists.<\/li>\n<\/ul>\n<\/blockquote>\n<\/li>\n<li>\n<blockquote><p>Serve an\u00a0<b>HSTS header<\/b>\u00a0on the base domain for HTTPS requests:<\/p><\/blockquote>\n<ul>\n<li>\n<blockquote><p>The\u00a0<tt>max-age<\/tt>\u00a0must be at least eighteen weeks (<tt>10886400<\/tt>\u00a0seconds).<\/p><\/blockquote>\n<\/li>\n<li>\n<blockquote><p>The\u00a0<tt>includeSubDomains<\/tt>\u00a0directive must be specified.<\/p><\/blockquote>\n<\/li>\n<li>\n<blockquote><p>The\u00a0<tt>preload<\/tt>\u00a0directive must be specified.<\/p><\/blockquote>\n<\/li>\n<li>\n<blockquote><p>If you are serving an additional redirect from your HTTPS site, that redirect must still have the HSTS header (rather than the page it redirects to).<\/p><\/blockquote>\n<\/li>\n<\/ul>\n<\/li>\n<\/ol>\n<p>If you satisfy these requirements, simply head here and fill out the form to <a href=\"https:\/\/hstspreload.org\/\" rel=\"nofollow\">submit your site to the HSTS preload list<\/a>.<\/p>\n<h2>What we Hashed Out (for Skimmers)<\/h2>\n<p>Here&#8217;s what we covered in today&#8217;s discussion:<\/p>\n<ul>\n<li>HTTP Strict Transport Security is a website header that forces browsers to make secure connections<\/li>\n<li>Websites should employ HSTS because it blocks protocol downgrades and cookie hijacking<\/li>\n<li>We recommend including your site on the HSTS preload list to block a small attack vector with first-time connections<\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>HTTP Strict Transport Security forces browsers to make secure HTTPS connections with websites. HTTP Strict Transport Security has been in the news a little bit lately thanks to Google&#8217;s decision&#8230;<\/p>\n","protected":false},"author":6,"featured_media":5131,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":"","tve_updated_post":"","tve_custom_css":"","tve_user_custom_css":"","tve_globals":{},"tcb2_ready":0,"tcb_editor_enabled":0,"tve_landing_page":"","_tve_header":"","_tve_footer":""},"categories":[130],"tags":[131,160,581,467],"class_list":["post-5128","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-everything-encryption","tag-google","tag-hsts","tag-ssl-certificate","tag-ssltls","post-with-tags"],"views":66877,"jetpack_featured_media_url":"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2017\/10\/iStock-629285904.jpg","_links":{"self":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts\/5128","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/users\/6"}],"replies":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/comments?post=5128"}],"version-history":[{"count":0,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts\/5128\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/media\/5131"}],"wp:attachment":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/media?parent=5128"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/categories?post=5128"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/tags?post=5128"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}