Live data from Hacker News

Firefox 83 introduces HTTPS-Only Mode

blog.mozilla.org

11–20 of 525 posts

Re: Firefox 83 introduces HTTPS-Only Mode

#11

There had better be an about:config option to turn this stupidity off. Perhaps one of the downvoters can explain why the implied opinion "Nobody should be able to access your site without clearance from a third-party gatekeeper" belongs on a site called "Hacker News." And no, it won't be opt-in for long. Read the rest of the page: "Once HTTPS becomes even more widely supported by websites than it is today, we expect…

Turn what stupidity off? The menu item that you can use to opt in to it?

Re: Firefox 83 introduces HTTPS-Only Mode

#12
post #8

What happens if i need to access localhost on http?

As described in the article HTTPS-Only mode is opt in, you can also disable it at will, you can add exceptions on a site-by-site basis, and even when it's on you are prompted on whether or not you wish to proceed to non-HTTPS sites.

hvhfjfhjvf

Re: Firefox 83 introduces HTTPS-Only Mode

#13

There had better be an about:config option to turn this stupidity off. Perhaps one of the downvoters can explain why the implied opinion "Nobody should be able to access your site without clearance from a third-party gatekeeper" belongs on a site called "Hacker News." And no, it won't be opt-in for long. Read the rest of the page: "Once HTTPS becomes even more widely supported by websites than it is today, we expect…

Did you read the article? It clearly states it's opt-in.

Re: Firefox 83 introduces HTTPS-Only Mode

#14

There had better be an about:config option to turn this stupidity off. Perhaps one of the downvoters can explain why the implied opinion "Nobody should be able to access your site without clearance from a third-party gatekeeper" belongs on a site called "Hacker News." And no, it won't be opt-in for long. Read the rest of the page: "Once HTTPS becomes even more widely supported by websites than it is today, we expect…

[deleted]

Re: Firefox 83 introduces HTTPS-Only Mode

#16

What happens if i need to access localhost on http?

You could start by reading the article, even only the first paragraph: > Firefox asks for your permission before connecting to a website that doesn’t support secure connections.

It could be a bit smarter and detect if connection is to a local server.

Re: Firefox 83 introduces HTTPS-Only Mode

#18
I’m surprised at the negative knee-jerk reaction. I actually love this idea immediately. It encapsulates something I kind of already wanted when using HTTPS Everywhere.

This doesn’t guarantee the transport is end-to-end secure; I’m sure plenty will strip the encryption at an LB and then possibly send it back over the internet. But, I think it’s a good addition nevertheless. Here’s to hoping for more DoH and encrypted SNI adoption as well. No good reason to leave anything unencrypted if it doesn't have to be.

(I’m less happy with Firefox’s approach to DoH rollout, but I’m still glad to see DoH gaining some traction. Let’s hope the end result is worth it...)

Re: Firefox 83 introduces HTTPS-Only Mode

#20
As a developer I likely won't use this feature much, considering most of our internal development sites are http only. For the general public it might be useful though, especially the auto-upgrade feature, protecting them from the lazy network operators that didn't add a proper auto-redirect.
Post reply on HN