I wonder how it will work against websites like http://neverssl.com (which helps me to log in to some wifi portals, HTTPS Everywhere shows the prompt for a temporary exception.)
An alternative I use is http://captive.apple.com (other OS vendors have their own). Which may have a higher chance of being detected by the portal (more likely to be white-listed) and triggering the prompt correctly.
Firefox 83 introduces HTTPS-Only Mode
51–60 of 525 posts
Re: Firefox 83 introduces HTTPS-Only Mode
#52I’m surprised at the negative knee-jerk reaction. I actually love this idea immediately. It encapsulates something I kind of already wanted when using HTTPS Everywhere. This doesn’t guarantee the transport is end-to-end secure; I’m sure plenty will strip the encryption at an LB and then possibly send it back over the internet. But, I think it’s a good addition nevertheless. Here’s to hoping for more DoH and encrypted…
Re: Firefox 83 introduces HTTPS-Only Mode
#53Re: Firefox 83 introduces HTTPS-Only Mode
#54I have been using HTTPS Everywhere for many years: https://www.eff.org/https-everywhere
Re: Firefox 83 introduces HTTPS-Only Mode
#55dom.security.https_only_mode = true
Re: Firefox 83 introduces HTTPS-Only Mode
#56There had better be an about:config option to turn this stupidity off. Perhaps one of the downvoters can explain why the implied opinion "Nobody should be able to access your site without clearance from a third-party gatekeeper" belongs on a site called "Hacker News." And no, it won't be opt-in for long. Read the rest of the page: "Once HTTPS becomes even more widely supported by websites than it is today, we expect…
> Perhaps one of the downvoters can explain why the implied opinion "Nobody should be able to access your site without clearance from a third-party gatekeeper" belongs on a site called "Hacker News." I didn't vote down, but ironically this is news to real hackers who will have a harder time doing mitm downgrade attacks once this is widespread. I believe that web browsers should alert users if a website uses a less se…
Re: Firefox 83 introduces HTTPS-Only Mode
#57Earlier quoted context omitted.
According to another comment, you can still allow certain sites through http, so your Internet dev sites are still fine but the global sites will be blocked by default
Sure, but we have like 50 different internal domains for different customers, so that would get annoying real fast ;)
Re: Firefox 83 introduces HTTPS-Only Mode
#58Great to see this built into firefox, I have been using HTTPS Everywhere https://www.eff.org/https-everywhere to achieve similar results, it won't warn you if it is not https (i think) but it will try and upgrade to https if it can. It is available for chrome and firefox. What particularly annoyed me was using http to sites which supported https.
IIRC HTTPS Everywhere works by having a whitelist of domains that are also accessible over https, and switches to https for those. So if a site isn't in the whitelist, it won't modify the request in any way.
Re: Firefox 83 introduces HTTPS-Only Mode
#59It's obvious I need to spend more time researching Gemini and similar things. The "web" is going to be a true monoculture very, very soon.
Re: Firefox 83 introduces HTTPS-Only Mode
#60It's obvious I need to spend more time researching Gemini and similar things. The "web" is going to be a true monoculture very, very soon.
Then there is the case of all the old computers that either lack the processing power or support for modern algorithms.