<?xml version="1.0" encoding='utf-8'?>
<!DOCTYPE wml PUBLIC "-//WAPFORUM//DTD WML 1.1//EN" "http://www.wapforum.org/DTD/wml_1.1.xml">
<wml>
<card id="card1" title="HTTP Strict Transport Security - Page 17 - Wikipedia">
<p>
<a accesskey="1" href="page.php?w=HTTP_Strict_Transport_Security&amp;p=16">1.Previous</a><br />
<a accesskey="3" href="page.php?w=HTTP_Strict_Transport_Security&amp;p=18">3.Next</a>
</p>
<p>records to declare HSTS Policy, and accessing them securely via <a href="page.php?w=DNSSEC">DNSSEC</a>, optionally with certificate fingerprints to ensure validity (which requires running a validating resolver to avoid <a href="page.php?w=Last_mile_%28telecommunications%29">last mile</a> issues).</p>

<p>Junade Ali has noted that HSTS is ineffective against the use of false domains; by using DNS-based attacks, it is possible for a man-in-the-middle interceptor to serve traffic from an artificial domain which is not on the HSTS Preload list, this</p><p>
<a accesskey="1" href="page.php?w=HTTP_Strict_Transport_Security&amp;p=16">1.Previous</a><br />
<a accesskey="3" href="page.php?w=HTTP_Strict_Transport_Security&amp;p=18">3.Next</a>
</p>

<do type="prev" label="Search">
        <go href="search.wml"/>
</do>

</card>
</wml>
