Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add link to actual list #173

Open
wants to merge 1 commit into
base: main
Choose a base branch
from
Open

Add link to actual list #173

wants to merge 1 commit into from

Conversation

hannob
Copy link

@hannob hannob commented Mar 24, 2019

I think it would be nice if the webpage for the HSTS preload list contained info where to actually get the preload list.

The link goes to the github mirror of the chromium source, because the original on googlesource does not support direct downloading of the raw file.

@lgarron
Copy link
Collaborator

lgarron commented Mar 25, 2019

What would you say the main reasons are that people need access to the full list? As with the public suffix list, there are issues with encouraging general consumption of the list. And most visitors to hstspreload.org are concerned about individual domains.

The link goes to the github mirror of the chromium source, because the original on googlesource does not support direct downloading of the raw file.

I don't think it's a good idea to link to the mirror, since it's not the canonical source.

@hannob
Copy link
Author

hannob commented Mar 26, 2019

There is no canonical source of direct download of that list, the mirror is the only one. I'd say this is an unfortunate limitation of googlesource, but I guess that's a separate issue.

As for the reason people might want to download the list I can only speak for myself, but I regularly want to check whether domains are in that list for research purposes, e.g. I might want to verify what security measures a company/service uses and just grep their domain in the list to see if they use preloading. Of course I can just put the link into my bookmarks, but I feel given there's an official page of the preload list not providing an easy way to get the actual list seems unusual.

@spaze
Copy link

spaze commented Sep 15, 2019

FWIW, the list in JSON can now be downloaded directly from cs.chromium.org: https://cs.chromium.org/codesearch/f/chromium/src/net/http/transport_security_state_static.json

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

3 participants