A modified clone of https://github.com/redpois0n/hsts-everywhere-chrome "Forces Chrome to use HTTP Strict Transport Security on all HTTPS connections https://chrome.google.com/webstore/detail/hsts-enforcer/ingdjdekfhnapeoiiinplcadnfimnnkh "

Emanuel Czirai e1a975ddb7 to ignore list 8 years ago
.gitignore eb6f4b3f4e ignore .swp files / vim 8 years ago
CONTRIBUTING.md 3d0857bd36 ignore that part 8 years ago
LICENSE 8193342bbd here's a license... 8 years ago
README.md 02628dcfd7 mention redir-loop mitigation 8 years ago
background.js e1a975ddb7 to ignore list 8 years ago
icon.png 693d2897c2 Icon 9 years ago
manifest.json 7a0bdb2fcc change loglevels to logflags 8 years ago
options.html dd42400e11 this quick link to extensions page won't work 8 years ago

README.md

hsts-everywhere-chrome

Forces Chrome/Chromium to use HTTP Strict Transport Security on all HTTPS connections, for all subdomains of the specific hostname you're trying to connect to. Also forces https on all urls, blocks http(but can allow it if you set a var). Can force disable HSTS, or can ignore hosts in hardcoded lists. Auto-ignores hosts that cause redir-loops eg. imdb.com and thus it http isn't allowed(which is the default) it will block the site, else it will load it on http; instead of entering redir-loop trying to https it!

Default max-age is 6 months. Change this in background.js in seconds

var max_age = "15570000";

Credits