HSTS for Ruby on Rails: Pros, Cons, and Safe Rollout
HSTS in Rails is one of those security wins that looks trivial right up until you break a domain for months. If you run a Rails app over HTTPS, you should probably send Strict-Transport-Security. But the real question for a developer team isn’t “should we use HSTS?” It’s “which HSTS policy should we ship, and how safely can we get there?” Rails makes this pretty easy, but the tradeoffs matter. A weak HSTS policy leaves downgrade risk on the table. An aggressive one can lock users and subdomains into HTTPS before your infrastructure is ready. ...