Hi everyone, is there a way to enable HTTP Strict ...
# fleet
j
Hi everyone, is there a way to enable HTTP Strict Transport Security in osquery?
k
Hi, @Joe! Great question. Osquery itself only communicates using https and doesn't interact with the browser directly, so it wouldn't apply on that end. This has definitely sparked conversation with the team about applying HSTS by default to Fleet itself. Please let me know if that doesn't clear things up for you!
j
@Kathy Satterlee thank you so much for that information. I'm new to osquery and i'm still learning the ins and outs of it so this information is definitely helpful. How are attacks such as SSL stripping mitigated in Osquery?