refresh my understanding, if i manually type "https" into the address bar, then i can't be MitM'ed through lack of HSTS, right?
Applications like Outlook will warn you about cert problems but still let you bypass them. This could be better on app side, but it’s a reality end users deal with. And when/if IT knows about it, it’s because the user complains that their laptop/Outlook is broken. The avg business user doesn't think about cert chains.
If you are, you’ll get a message that the very isn’t valid.
Unless there’s an attack on cert providers or someone adds a cert to your device.
The cert approach can be seen in some corporate environments.
How does HSTS help with that?
You mean HPKP? AFAIK it isn't an extension, but rather another feature. Also, it's deprecated at this point.