3 ms·
I think you're missing the part where a non-upgraded connection will be treated by the client as insecure and untrustable.
by spb 10y ago
I think you're missing the part where a non-upgraded connection will be treated by the client as insecure and untrustable.
- thedufer 10y agoSo the suggestion is that in 1994 (when the https protocol was introduced) we should have put big scary warnings on every non-ssl site? I don't see how that could've gone well. It's now 22 years later and people still aren't ready for that.