HSTS removes the insecure choice after a browser has learned the policy, while preload can protect the first visit too
HSTS tells a browser never to connect to this site unencrypted again.
The gap is that the browser has to be told at least once, so the very first visit is still exposed to being downgraded. Preloading closes that by shipping the instruction inside the browser itself, before any visit happens. It is one of the few protections that is genuinely set and forget, with the caveat that removal is slow if you ever need it.
More on TLS and PKI
- TLS encrypts a connection, not endpoint intentionsA sealed pipe to a stranger
- Certificates bind keys to names through trust chainsHeld together by a chain of seals
- Certificate expiry creates operational pressureEvery one of them runs out
- Private-key compromise survives a valid certificateThe certificate is fine
- OCSP stapling moves status evidence closerThe proof comes stapled on
- Mutual TLS authenticates both endsBoth of you show papers
