* top 1 banking, top 18 FR https://www.ssllabs.com/ssltest/analyze.html?d=labanqueposta... no HSTS
* top 2 banking, top 20 FR https://www.ssllabs.com/ssltest/analyze.html?d=credit-agrico... no HSTS
* top 1 taxes, top 30 FR https://www.ssllabs.com/ssltest/analyze.html?d=www.impots.go... with CAA, HSTS (not preload), OCSP Must-Staple! (that's a surprise)
* top 3 banking, top 45 FR https://www.ssllabs.com/ssltest/analyze.html?d=caisse%2depar... no HSTS
Hopefuly, by 2030 banks will have caught up to the 2018 standard for "secure".
Because HSTS gets you most of the protection you need while being able to recover if something goes horribly wrong.
Set your HSTS timeout to greater than the gap between user visits and it does prevent active MitM.
You're only unprotected for first time visits being actively intercepted or particularly long gaps where HSTS can expire (both of which are hard targets).
Applications like Outlook will warn you about cert problems but still let you bypass them. This could be better on app side, but it’s a reality end users deal with. And when/if IT knows about it, it’s because the user complains that their laptop/Outlook is broken. The avg business user doesn't think about cert chains.
If you are, you’ll get a message that the very isn’t valid.
Unless there’s an attack on cert providers or someone adds a cert to your device.
The cert approach can be seen in some corporate environments.
How does HSTS help with that?
You mean HPKP? AFAIK it isn't an extension, but rather another feature. Also, it's deprecated at this point.