Fun fact: HSTS
https://securityheaders.io/?q=www.uspto.gov&followRedirects=...
HSTS is 1 year at the time this comment is posted. They're in for some pain.
https://securityheaders.io/?q=www.uspto.gov&followRedirects=...
HSTS is 1 year at the time this comment is posted. They're in for some pain.
They are basically going to be DOSing a huge segment of users who've previously had that header set on their browsers...they're also violating the OMB mandate that requires TLS for all government sites...it is a rather strange move, I can't imagine there is a good reason for it.
EDIT If it is for portal.uspto.gov then HSTS is a non-issue but still a very bad move.
Is it? I still see HSTS from portal.uspto.gov with the same age.
doesn't seem to show anything for the domain