Earlier quoted context omitted.
This is a legitimate concern, but I think the so-called dire consequences are a bit overblown. Major browser vendors like Google and Mozilla don't change their policies in a vacuum while the rest of the world stays static. The move to "deprecate" HTTP is an explicit attempt to manipulate the rest of the world into making SSL easier and more affordable. It is unfair to evaluate this proposal in isolation without consi…
> The move to "deprecate" HTTP is an explicit attempt to manipulate the rest of the world into making SSL easier and more affordable. It is unfair to evaluate this proposal in isolation without considering the market upheaval that it is very much intended to trigger. I'd love to believe this but I've never once seen the https-only nazis bring up this issue on their own, or show any concern for the fact that it will l…
The plan is to disable some of the "more dangerous" features when the page is requested over HTTP, in order to entice webmasters to adopt SSL. The list hasn't even been written yet, but I'm guessing that most of those features will be fancy javascript and third-party plugins like Flash. Which you probably shouldn't rely on being enabled in the first place.
I personally wouldn't mind if every insecure page behaved as if I had NoScript & NoFlash enabled by default.
You may be right about the excessive idealism of so-called HTTPS nazis on some online forums, but I'm pretty sure that the people in charge at Google and Mozilla are more level-headed and realistic.
> the goal of this effort is to send a message to the web developer community that they need to be secure