"Additional, HSTS (with preloading) is quite widely deployed (especially at big cloud services), which makes plain text downgrade attacks hard to deploy."
looooooooooooool
Turns out, that was a lie
looooooooooooool
Turns out, that was a lie
Or do you mean that downgrade attacks are still easy to deploy? Under what circumstances?