• caglararli@hotmail.com
  • 05386281520

Ignore HSTS preloading in browsers [migrated]

Çağlar Arlı      -    16 Views

Ignore HSTS preloading in browsers [migrated]

Google Chrome (and other browsers) do a great job preventing the user from viewing non-TLS sites or sites with invalid certificates by using HSTS preloading. So good actually that I can't find a way to open the site in Google Chrome at all.

chrome://net-internals/#hsts allows you to temporarily remove HSTS for a domain, but only if it's not preloaded.

As an admin and security guy, I sometimes have to look at sites over http even though they use HSTS preloading. What is the best way to do this? I primarily use Chrome, but would also appreciate instructions for Firefox, Edge and Safari.