Live data from Hacker News

Chrome’s address bar will use https:// by default

blog.chromium.org

261–270 of 463 posts

Re: Chrome’s address bar will use https:// by default

#261
post #111

I wish there was a solution for those of us who develop web interfaces for embedded products designed to live on LAN, often without any internet access and no well defined domain name. I'm all for HTTPS everywhere but right now for my products it's either: https with self-signed certificate, which basically makes any modern browser tell its user that they're in a very imminent danger of violent death should they deci…

IMHO, what's needed is a way for appliances to obtain a real, permanent global domain name (and therefore certificates, email, etc.).

There's a bunch of mostly-obsolete rules that assume domains are held by organizations with full-time staffs (like whois contact records, per-domain ICANN fees, UDRP, etc.) a tld like ".thing" that allows non-humans to claim permanent global names on a first-come-first-serve basis would let autonomous hardware devices integrate with the existing infrastructure without hacks and exceptions. Maybe a ccTLD could be convinced to do this?

Re: Chrome’s address bar will use https:// by default

#262

Earlier quoted context omitted.

>HTTPS adoption is now very high[1] I posted this in a separate comment and I will post it again. https://certbot.eff.org/hosting_providers HTTPS adoption is hard enough that the wast majority of shared hosting providers haven't automated cert provisioning and are delegating this process to their users. The push towards forced HTTPS has significant costs, which most people in this filter bubble don't want to honestly…

> The push towards forced HTTPS has significant costs, which most people in this filter bubble don't want to honestly discuss. I agree, but I'll push back by saying that delaying HTTPS adoption and getting lax about it has a much higher cost -- and that is similarly a cost that most people pushing back against HTTPS either downplay or refuse to acknowledge. And more than that, those critics have shown that they're no…

Cloudflare does MITM. MITM is cited as a reason in this thread for force HTTPS upon everyone, even on static blog pages. Kind of ironic.

Re: Chrome’s address bar will use https:// by default

#263
post #136

Earlier quoted context omitted.

It's worrying how they are improving the case for "70%" scenarios, while crippling it for the other 30%, without recourse. It's not even funny any more. What happens with offline LAN? And the ideal IoT devices that we would all want to have? (I mean those we dream about in all IoT HN posts, where the rants typically are that no internet connection should be needed for most of these kinds of devices) What about offlin…

70% of scenarios? If I were to guess, it would be 70% of your time that your happy with https, and 30% you don't. But its 99.9% or higher in reality. Also, did you know 80% of facts are made up? XD

That number was totally made up, of course :) that's why I quoted it... didn't really want to be too pedant and explicitly say it, but maybe I should have.

Re: Chrome’s address bar will use https:// by default

#264

Earlier quoted context omitted.

> The push towards forced HTTPS has significant costs, which most people in this filter bubble don't want to honestly discuss. I agree, but I'll push back by saying that delaying HTTPS adoption and getting lax about it has a much higher cost -- and that is similarly a cost that most people pushing back against HTTPS either downplay or refuse to acknowledge. And more than that, those critics have shown that they're no…

Cloudflare does MITM. MITM is cited as a reason in this thread for force HTTPS upon everyone, even on static blog pages. Kind of ironic.

In the same way that any webhosting company "does MITM", your loadbalancer "does MTIM", ... The term makes little sense for a party that's explicitly part of the hosting infrastructure a site owner choose to handle HTTPS.

Re: Chrome’s address bar will use https:// by default

#265
post #236

Earlier quoted context omitted.

Is it the case that self-signed certs don't work in iOS at all? I'm looking around, and I appear to see tutorials for how to properly configure one in iOS. https://medium.com/collaborne-engineering/self-signed-certif...

Yeah, I don't know what OP is talking about, I'm using one on my iPhone right now. Enterprises deploy them all the time. It is true, that in recent versions of iOS (in the past five years or so), you have to install the certificate in Safari, then go to Settings->General->About, scroll all the way down, and manually trust the certificate (to ensure you really know what you're doing by enabling it). And iOS doesn't ma…

If you are talking about installing the Root CA in the iPhone, yeah. That's how I do it in my development devices.

But for a user, iOS Safari (not Safari for MacOS) doesn't show any certificate warning that the user can accept, like other browsers. In fact, it just fails absolutely silently. You'd have to connect it to a Mac and open up the developer tools on the desktop's Safari, to see the errors that are being printed on the JS console.

Otherwise, you'd just be left wondering why it just doesn't work like all the other browsers.

Re: Chrome’s address bar will use https:// by default

#266

Earlier quoted context omitted.

I'm wondering if the tested Firefox install has enabled DoH?

Oh interesting. Firefox says it's both enabled and set to use 1.1.1.1, and I figured that nothing would resolve if it wasn't... but if https://1.1.1.1/help is correct then it's not actually working and something else is happening. I know I tried setting and disabling that when I was testing but I saw no change. I don't remember setting 1.1.1.1 but I may have enabled DoH. I'll see if changing the DNS server in firefox…

FWIW, I've only seen the issue you reported when resolving a Cloudflare hosted site through Cloudflare dns, with Firefox as the client. Refreshing multiple times seemed to work.

I haven't had the time to investigate it when it occurred; anecdata.

I have wondered if it's related to handing off from the CF balancer to the sites tls.

Re: Chrome’s address bar will use https:// by default

#267
post #111

I wish there was a solution for those of us who develop web interfaces for embedded products designed to live on LAN, often without any internet access and no well defined domain name. I'm all for HTTPS everywhere but right now for my products it's either: https with self-signed certificate, which basically makes any modern browser tell its user that they're in a very imminent danger of violent death should they deci…

The article says

> IP addresses, single label domains, and reserved hostnames such as test/ or localhost/ will continue defaulting to HTTP.

I don't think this affects you. If you are accessing a device on your LAN, you either use its IP address, or if you use DNS, you must be using your own DNS resolver then. In that case you can just use a single-label domain name such as http://media/ and you can omit the "http://" in that case. This is also the case for many enterprise networks. Tip: you need to enter a trailing slash to tell Chrome is a single-label domain, otherwise Chrome will think you want to search.

I see nothing to worry about.

Re: Chrome’s address bar will use https:// by default

#268
post #111

I wish there was a solution for those of us who develop web interfaces for embedded products designed to live on LAN, often without any internet access and no well defined domain name. I'm all for HTTPS everywhere but right now for my products it's either: https with self-signed certificate, which basically makes any modern browser tell its user that they're in a very imminent danger of violent death should they deci…

Seems like a browser could treat the scenario when a user types an IP address differently from a normal domain name resolution (eg even just changing the messaging to be less scary). If you're actually using domain names on your LAN maybe you just have to bite the bullet and sign certificates too. You don't need internet access to have a properly signed certificate.

what about every major network that is not a very small bussiness or home network?

Split DNS is used all across to globe to build internal networks.

Re: Chrome’s address bar will use https:// by default

#269

Will you still need HSTS Preload going forward (for Chrome)?

Absolutely. You need the HSTS-preload list so that even when HTTPS fails on the first visit to a HSTS-protected domain, the browser will still refuse to fall back to plain HTTP.
Post reply on HN