Conversation

is there any rational basis for adding httponly cookies, HSTS, or HTTPS redirect headers for web svcs that literally only listen on 443 for TLS? (context: not a web server, but custom Go network service; there is no "port 80"). Hard pressed to think of any.
1
2
Replying to and
When you say "only listen on 443 for TLS" you mean "When the legitimate site only listens on 443 for TLS"... but there's little stopping an attacker from pretending like there's a HTTP site running on port 80." So that's why you want HSTS+preload.
2
7