Hi, I see HTTP Strict Transport Security (HSTS) is now supported in most web servers and browsers, and prevents Tls downgrade attacks (such as SSL Stripping). Does anyone know if this is supported by the Android API for http requests sent by apps? (or if this is relevant for apps) Thanks
-- You received this message because you are subscribed to the Google Groups "Android Security Discussions" group. To unsubscribe from this group and stop receiving emails from it, send an email to [email protected]. To post to this group, send email to [email protected]. Visit this group at http://groups.google.com/group/android-security-discuss. For more options, visit https://groups.google.com/d/optout.
