A couple of website testers suggest that my website is not meeting best security practices.
They say to prevent SSL stripping (wifi hotspot attacks) I should disable any initial contact via http.
The code or setting is
Strict-Transport-Security: max-age=31536000; includeSubDomains; preload
Does anyone know or actually use this?