5 ms·
Awesome. Thanks a lot! Can we now add SSL to the website please, since VLC already appeared as attack vector in tools like FinFisher.
by sleepless 9y ago
Awesome. Thanks a lot!
Can we now add SSL to the website please, since VLC already appeared as attack vector in tools like FinFisher.
- jbk 9y agoSSL is already there.
- icebraining 9y agoWhy doesn't it auto-redirect? (Not a criticism, just curiosity.)
- sleepless 9y agoKey question indeed. And HSTS would be the cream on top. But let's start with redirects.
- snakeanus 9y agoWhat is the point of the redirects? If the user wants to use the https version he would directly go to that (either manually or by using something like httpseverywhere). Why force to user to use a specific one?
- icebraining 9y agoBecause most people have no idea what HTTPS is, let alone that you can manually switch between the two. Nor do they know what a browser addon is, let alone knowing that specific one exists.
- snakeanus 9y agoIn that case they should deal with the consequences of their ignorance.
- icebraining 9y agoWhy?
- jbk 9y agoIE. But that is soon over. You should see SSL from Google though.
- sleepless 9y agoIs there an existing ticket for redirects?
- jbk 9y agoYes. But not in the VLC tracker, because it is not a VLC issue.
- Hello71 9y agohttps://www.w3.org/TR/upgrade-insecure-requests/#feature-detect https://www.w3.org/TR/upgrade-insecure-requests/#feature-det...
- pilif 9y agoBecause of lacking SNI support? You can try an Ajax request or loading a picture over SSL and then redirect with JS if it doesn't fail. If the SSL site serves HSTS headers, all SNI supporting browsers will in the future default to HTTPS independently of the kludgey redirect (because all browsers that support HSTS also support SNI). Sure. An unconditional redirect would be better, but that requires a dedicated IP