Live data from Hacker News

Firefox 83 introduces HTTPS-Only Mode

blog.mozilla.org

101–110 of 525 posts

Re: Firefox 83 introduces HTTPS-Only Mode

#101
post #97
post #87

Earlier quoted context omitted.

I want my OS to do DNS - including DOH, not my browser. I want a single source for my DNS I want my network to tell me a DNS server to use. As I own my computer I can override that, but much of the time I want to use the network provided DNS server.

At least in my case network provided DNS are the worst, Full of spyware, and tracking.

They're referring to the local network configuration.

Many sysadmins will hate this.

> Full of spyware, and tracking.

What do you use? Google?...

Re: Firefox 83 introduces HTTPS-Only Mode

#102
post #98
post #93

I'm for this. Any computer capable of running FF83 is powerful enough to use HTTPS everywhere. What it doesn't do, is force good TLS - there's nothing to stop a site using a weak algorithm, SSLv2/3, or old TLS versions. It also wrecks network-level caching using appliances like Squid.

> What it doesn't do, is force good TLS - there's nothing to stop a site using a weak algorithm, SSLv2/3, or old TLS versions. TLS 1.0 and 1.1 were disabled in Firefox 78 in June.

That's good news. I know there was some flip-flopping over this because of covid and gov sites requiring old encryption. Great to hear that it's now done with.

Re: Firefox 83 introduces HTTPS-Only Mode

#103
post #23

I wonder how it will work against websites like http://neverssl.com (which helps me to log in to some wifi portals, HTTPS Everywhere shows the prompt for a temporary exception.)

It will say "this website doesn't support https, do you want to connect anyway"

Re: Firefox 83 introduces HTTPS-Only Mode

#104
post #23

I wonder how it will work against websites like http://neverssl.com (which helps me to log in to some wifi portals, HTTPS Everywhere shows the prompt for a temporary exception.)

I'll have to remember that for next time I get "wireless on the train doesn't work, I get some security error" via SMS. Last time I pointed them at one of my sub-domains that still serves plain HTTP to bring up the captive portal (which wasn't trying to charge, or apparently even advertise, the network just insisted you hit it at least once to be told "Hello!" and presumably have your MAC added to the whitelist for a…

Captive portals are not unique to wireless networks so if you are gonna register a new name you might wanna go with something more generic (like "isnetworkbroken.com" or something like that).

Re: Firefox 83 introduces HTTPS-Only Mode

#106
post #87
post #18

I’m surprised at the negative knee-jerk reaction. I actually love this idea immediately. It encapsulates something I kind of already wanted when using HTTPS Everywhere. This doesn’t guarantee the transport is end-to-end secure; I’m sure plenty will strip the encryption at an LB and then possibly send it back over the internet. But, I think it’s a good addition nevertheless. Here’s to hoping for more DoH and encrypted…

I want my OS to do DNS - including DOH, not my browser. I want a single source for my DNS I want my network to tell me a DNS server to use. As I own my computer I can override that, but much of the time I want to use the network provided DNS server.

I think in 2020 we can declare that Californian companies dictate what you can and can't do on your computer, which DNS server to use and what goes through a VPN client and what does not. The same way they decide what is a fact, what is newsworthy and what you are allowed to read / post.

Re: Firefox 83 introduces HTTPS-Only Mode

#107

This is a great step, but I wish browsers would allow you to set domains that are considered to be secure origins in all cases. I have a decent intranet with transport security guaranteed by VPN, but because it isn't "HTTPS" I can't access tons of browser features.

Isn't this what HSTS does? Maybe a way to manually add domains to the list would be good.

I think GP is asking for a whitelist of HTTP-only domains the browser should consider safe.

Re: Firefox 83 introduces HTTPS-Only Mode

#108

This is a great step, but I wish browsers would allow you to set domains that are considered to be secure origins in all cases. I have a decent intranet with transport security guaranteed by VPN, but because it isn't "HTTPS" I can't access tons of browser features.

In Chrome/Chromium-based browsers, you do exactly that here: chrome://flags/#unsafely-treat-insecure-origin-as-secure

Re: Firefox 83 introduces HTTPS-Only Mode

#109

There's a phenomenon I observe quite regularly in tech. A problem exists and creative people develop an innovative solution to said problem. The solution then becomes popular and a singular goal of uncreative people who deploy said solution everywhere and push it to its logical extreme. I remember seeing this in the mid-2000s when HTML tables were shunned in favour of "divs". I saw people reinventing tables using div…

Couldn't agree more. Benefits of using HTTPS for most websites are doubtful, but the costs are real, in overhead and caching problems. We don't need the same level of security everywhere. (I'm not even sure we need that much "security" in general, but that's another topic.)

It's sad to see Firefox continuing to bother itself with solving non-problems while serious bugs go uncorrected for years.

Post reply on HN