What is HSTS, and why does it stop you bypassing a certificate warning?
HTTP Strict Transport Security is a instruction from a website telling your browser to only ever connect to it over HTTPS — and to refuse to proceed if anything is wrong, without offering you a way round it.
The attack it prevents. Even on a site that redirects HTTP to HTTPS, the first request is frequently plain HTTP — typing a domain without a scheme, or following an old link. An attacker on the network can intercept that initial unencrypted request and keep the connection on HTTP, quietly relaying content while reading and modifying it. This is SSL stripping, and it works because the user never sees a warning — the page simply looks normal without a padlock, which almost nobody notices.
How HSTS closes it. The site sends a header specifying a max-age in seconds. For that period, the browser:
Rewrites any HTTP request to HTTPS internally, before it leaves the machine. No plain-text request is ever sent.
Refuses to allow the user to bypass certificate errors. This is the part people encounter. On an ordinary site, an invalid certificate produces a warning with an "accept the risk and continue" option. On an HSTS site, that option does not exist — the connection is simply blocked.
Why that strictness is deliberate. The bypass option is the weak point of certificate warnings: users click through them routinely. HSTS removes the choice for sites that have declared they should always be secure, which is the entire security benefit.
Directives: includeSubDomains extends it to everything beneath the domain; preload requests inclusion in a list compiled into browsers themselves, so protection applies even on a first-ever visit — closing the remaining gap, at the cost of being slow and awkward to reverse.
When you will run into it legitimately: captive portals on hotel and airport Wi-Fi, which intercept traffic to show a login page; corporate networks performing TLS inspection; a genuinely expired certificate; and a clock set wrongly on your device, which makes valid certificates appear invalid.
Clearing an HSTS entry is possible in browser settings, and should be a last resort — the warning is usually correct.