I’m surprised at the negative knee-jerk reaction. I actually love this idea immediately. It encapsulates something I kind of already wanted when using HTTPS Everywhere. This doesn’t guarantee the transport is end-to-end secure; I’m sure plenty will strip the encryption at an LB and then possibly send it back over the internet. But, I think it’s a good addition nevertheless. Here’s to hoping for more DoH and encrypted…
Could this or HTTPS Everywhere warn you when a site is known for encryption stripping? I think this happens on the free cloudflare tier and we can’t determine that.
Firefox 83 introduces HTTPS-Only Mode
61–70 of 525 posts
Re: Firefox 83 introduces HTTPS-Only Mode
#62Finally! I've been waiting for HTTPS to be the default for a while now. From a security standpoint it's annoying that bar something like HSTS it's trivial for a man in the middle to force a downgrade to non-secure HTTP. The fix is to force yourself as a user to look for the lock symbol in the address bar, but that's terrible from a usability perspective. However, I'm not sure whether it'd be best to make this the mod…
Re: Firefox 83 introduces HTTPS-Only Mode
#63There had better be an about:config option to turn this stupidity off. Perhaps one of the downvoters can explain why the implied opinion "Nobody should be able to access your site without clearance from a third-party gatekeeper" belongs on a site called "Hacker News." And no, it won't be opt-in for long. Read the rest of the page: "Once HTTPS becomes even more widely supported by websites than it is today, we expect…
Did you read the article? It clearly states it's opt-in.
Re: Firefox 83 introduces HTTPS-Only Mode
#64Earlier quoted context omitted.
HTTPS is not about gatekeeping, you can use "let's encrypt" for free certificates for any domain. HTTPS-only is about forcing all traffic to be encrypted by banning clear-text traffic. I've been using the "HTTPS everywhere" extension for years and it's great.
yes it is. someone has to give you a certificate which the users browser accepts. even if its free today. lets say a simple website which someone uses to display some holiday pictures. why would we need https here, if there is no login or anything like that? it just adds an extra hurdle for not so tech-savvy users and increases the trend to abolish small private websites.
Imagine if those pictures have been replaced by something else. If you can't think of a long list of replacement images that could be very useful for a spearphishing attack, then you're not having enough imagination.
This attack could also be used to get the poster of the photos in trouble.
Re: Firefox 83 introduces HTTPS-Only Mode
#65Re: Firefox 83 introduces HTTPS-Only Mode
#66It's obvious I need to spend more time researching Gemini and similar things. The "web" is going to be a true monoculture very, very soon.
Using https is making the web a monoculture?
Re: Firefox 83 introduces HTTPS-Only Mode
#67I have been using HTTPS Everywhere for many years: https://www.eff.org/https-everywhere
Yes, but one less extension with access to all your history, passwords and all other info.
Re: Firefox 83 introduces HTTPS-Only Mode
#68Re: Firefox 83 introduces HTTPS-Only Mode
#69I've used this for a few months now. It ugrades non-https connections on secure pages automatically. Very useful. Even big sites like microsoft, google images serve things over http dom.security.https_only_mode = true