Securing the Web with HSTS-Enforced

Conference Paper (2026)
Author(s)

Aaron van Diepen (TU Delft - Electrical Engineering, Mathematics and Computer Science)

Adrian Zapletal (TU Delft - Electrical Engineering, Mathematics and Computer Science)

Fernando Kuipers (TU Delft - Electrical Engineering, Mathematics and Computer Science)

Research Group
Networked Systems
DOI related publication
https://doi.org/10.23919/IFIPNetworking70592.2026.11579066 Final published version
More Info
expand_more
Publication Year
2026
Language
English
Research Group
Networked Systems
Publisher
IEEE
ISBN (electronic)
9783903176829
Event
2026 IFIP Networking Conference, IFIP Networking 2026 (2026-05-24 - 2026-05-27), Lugano, Switzerland
Downloads counter
31
Reuse Rights

Other than for strictly personal use, it is not permitted to download, forward or distribute the text or part of it, without the consent of the author(s) and/or copyright holder(s), unless the work is under an open content license such as Creative Commons.

Abstract

TLS stripping attacks expose sensitive web traffic by forcing secure HTTPS connections to fall back to unencrypted HTTP. At present, protection against these attacks relies on website operators explicitly opting into security by deploying mechanisms such as HTTP Strict Transport Security (HSTS) headers. These mechanisms have significant limitations: some are weak or difficult to configure, which raises the risk of misconfiguration and reduces practical adoption; others violate HTTP backward compatibility; at least one can even be abused to enable unintended user tracking.We introduce HSTS-Enforced, a mechanism that eliminates the remaining attack surface for TLS stripping while still allowing operators to securely specify that their websites need to be accessed over HTTP when necessary, thereby maintaining accessibility. To achieve this, we flip the current opt-in security model to an opt-out model: all connections default to HTTPS, and operators can explicitly opt out if their websites require HTTP using so-called HTTP-Required indicators. We propose two such HTTP-Required indicators: a new DNS record and an HTTP-Required Preload list. We evaluate HSTS-Enforced under multiple deployment scenarios, demonstrating that it blocks all practical TLS stripping attempts while maintaining compatibility for sites that require HTTP-without introducing overhead in the typical case. Finally, we outline a practical transition path to accelerate global adoption.

Files

– Personal use only – Dutch Copyright Act (Article 25fa)
warning

File under embargo until 30-12-2026