You could be.
If you are, you’ll get a message that the very isn’t valid.
Unless there’s an attack on cert providers or someone adds a cert to your device.
The cert approach can be seen in some corporate environments.
If you are, you’ll get a message that the very isn’t valid.
Unless there’s an attack on cert providers or someone adds a cert to your device.
The cert approach can be seen in some corporate environments.
How does HSTS help with that?
You mean HPKP? AFAIK it isn't an extension, but rather another feature. Also, it's deprecated at this point.