Ok, so that works for Chrome, but every other application is still going to be subject to an MITM attack if their users try to connect via http?
Firefox have some scripts which go through and check to make sure everything still on the Chrome list is still announcing the preload headers, and will autoremove if that isn't that case, IIRC. I wouldn't be too shocked if Apple/Microsoft were doing something similar.
Is there any documentation for these browsers that officially say exactly what they're doing and how their preload lists are generated?
https://wiki.mozilla.org/SecurityEngineering/HTTP_Strict_Tra...