You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
I understand that switchting back to http:// would be a violation against Article 32 EU GDPR.
I understand that removing my domain from the HSTS preloading list would make me and my users more likely vulnerable to downgrade attacks and I confirm my liability about this.
Although there are stronger incentives for HTTPS, my impression is that a scarier checklist will not necessarily help discourage the kinds of removal requests we see: https://crbug.com/527947
We should also not overstate things: Article 32 of the GDPR says security should be "appropriate to the risk", bad press purely due to lack of preload HSTS is actually a fairly low risk for the kinds of sites that ask for removal, and we should not be condescending to site operators who are often making a frustrating tradeoff already.
Also note that the removal form right now purposely has no checkboxes. If we add some stronger language, I think it would be better to add it to the page directly.
The text was updated successfully, but these errors were encountered: