3 ms·
Again, I'm suggesting browsers should continue to display a warning if a site that was previously served over an authenticated connection stops being served ove
by phlo 10y ago
Again, I'm suggesting browsers should continue to display a warning if a site that was previously served over an authenticated connection stops being served over an authenticated connection. In this case, an attacker could only turn off SSL if a site has never been encountered before. High-value sites are included in HSTS lists already, so this gap can be bridged.
Right now, attackers can quitely turn off SSL for most sites if they just strip it from the connection; requesting over HTTPS and re-serving over HTTP. The majority of users types "example.org" into their address bar, not "https://example.com" https://example.com". Most users won't notice, especially not if the favicon is replaced with a fake green padlock.
> Just get a real certificate, or have your users add your certificate to the trust store manually.
Yep. Given the availability of Let's Encrypt (and others), the discussion is mostly moot anways :)