3 ms·
Encrypt All Sites Eligible doesn't prevent http to .onion sites. See the check here: https://github.com/EFForg/https-everywhere/blob/bcaf7bdecf147c2a46d7ed73bc
by hcs 6y ago
Encrypt All Sites Eligible doesn't prevent http to .onion sites.
See the check here: https://github.com/EFForg/https-everywhere/blob/bcaf7bdecf147c2a46d7ed73bce64389d828d865/chromium/background-scripts/background.js#L370 https://github.com/EFForg/https-everywhere/blob/bcaf7bdecf14...
Edit: Which is not to say that there aren't rules forcing some .onion sites to https, there are. Encrypt All Sites Eligible (httpNowhereOn) just knows it doesn't have to worry about un-rewritten http .onion addresses. So it really is a good idea to turn it on, and think hard before allowing an exception.
- bilegeek 6y agoHuh. TIL. I guess it also depends on your threat model. If you are only browsing and in "Safest" mode, I suppose it's tolerable. But I agree that logging into anything requires EASE to be on.