31 ms·
Firefox 83 introduces HTTPS-Only Mode
- philshem 6y agoThis feature is not enabled as default in Firefox 83. To enable it, make sure you have Firefox 83 installed. Then go to about:preferences#privacy and scroll down to the section "HTTPS-Only Mode" and make your selection.
- fredsted 6y agoJudging from the comments here, they really should've added the word "optional" in the title.
- chrismorgan 6y ago“Mode” means “a way that it can operate”.
- doublerabbit 6y ago"optional mode" problem solved.
- chrismorgan 6y ago“HTTPS-Only Optional Mode” reads terribly and is much more subject to confusion than “HTTPS-Only Mode” was.
- joveian 6y agoIt is optional for now, but as they say at the end the intent is to eventually always require HTTPS.
- StreamBright 6y agoWhat happens if i need to access localhost on http?
- jstsch 6y agoFrom the article: Firefox asks for your permission before connecting to a website that doesn’t support secure connections.
- fiskfiskfisk 6y agoIt's explained in the post: > For the small number of websites that don’t yet support HTTPS, Firefox will display an error message that explains the security risk and asks you whether or not you want to connect to the website using HTTP. Here’s what the error message looks like: ..
- iso1631 6y ago"Firefox asks for your permission before connecting to a website that doesn’t support secure connections." That suggests it will ask you for permission, presumably with a "always remember this choice" option.
- pedrogpimenta 6y agoYou could start by reading the article, even only the first paragraph: > Firefox asks for your permission before connecting to a website that doesn’t support secure connections.
- agilob 6y agoIt could be a bit smarter and detect if connection is to a local server.
- Doctor_Fegg 6y agoNo need for snark. It's a legit question and buildfocus's answer below is relevant: "browsers generally treat localhost and/or 127.0.0.1 as secure origins in themselves anyway"
- StreamBright 6y agoI have read it, I was wondering about localhost explicitly.
- 6y ago
- CamperBob2 6y agoThere had better be an about:config option to turn this stupidity off. Perhaps one of the downvoters can explain why the implied opinion "Nobody should be able to access your site without clearance from a third-party gatekeeper" belongs on a site called "Hacker News." And no, it won't be opt-in for long. Read the rest of the page: "Once HTTPS becomes even more widely supported by websites than it is today, we expect it will be possible for web browsers to deprecate HTTP connections and require HTTPS for all websites. In summary, HTTPS-Only Mode is the future of web browsing!" This is something you should be speaking up against.
- everfree 6y agoTurn what stupidity off? The menu item that you can use to opt in to it?
- Deukhoofd 6y agoDid you read the article? It clearly states it's opt-in.
- dalu 6y agoAt first it's opt-in then it becomes the default setting. Are you a developer? If you are then you should be used to thinking at least 2 steps ahead and just seeing what's literally visible in front of you.
- deleted 6y ago[deleted]
- kanox 6y agoHTTPS is not about gatekeeping, you can use "let's encrypt" for free certificates for any domain. HTTPS-only is about forcing all traffic to be encrypted by banning clear-text traffic. I've been using the "HTTPS everywhere" extension for years and it's great.
- sildur 6y agoYou can use let's encrypt... until you can't. And then, after all browsers had deprecated HTTP, it will be time to seriously rake all website owners for certificate money. It is pretty brilliant, if you ask me.
- stanislavb 6y ago...and I still still http-only sites from time to time.
- everfree 6y agoYour post is brief, and has a grammar error that makes it harder to understand.
- Jestar342 6y agothe second "still" is meant to be "sell" or "make".
- everfree 6y agoThat helps a bit. I could be wrong, but I think the common belief is that professionally-developed HTTP-only sites don't really have a place anymore on the 2020s internet due to HTTP/2, security, referral tracking, and SEO limitations.
- eznzt 6y agoI think it means "see"
- Jestar342 6y agoThat makes a lot more sense than my suggestions.
- deleted 6y ago[deleted]
- jchw 6y agoI’m surprised at the negative knee-jerk reaction. I actually love this idea immediately. It encapsulates something I kind of already wanted when using HTTPS Everywhere. This doesn’t guarantee the transport is end-to-end secure; I’m sure plenty will strip the encryption at an LB and then possibly send it back over the internet. But, I think it’s a good addition nevertheless. Here’s to hoping for more DoH and encrypted SNI adoption as well. No good reason to leave anything unencrypted if it doesn't have to be. (I’m less happy with Firefox’s approach to DoH rollout, but I’m still glad to see DoH gaining some traction. Let’s hope the end result is worth it...)
- guitarlimeo 6y ago> This doesn’t guarantee the transport is end-to-end secure; I’m sure plenty will strip the encryption at an LB and then possibly send it back over the internet. Hijacking this a bit - If plenty are stripping the encryption at an LB (like Cloudflare for example), how can you be sure that NSA is not wiretapping in Cloudflare's infrastructure where it is not encrypted? Seems like a really easy way to get unencrypted data and not care about if everything is HTTPS or not. Are there any counterexamples to this? Do we know that Cloudflare or AWS is not doing this?
- arebhaibhai 6y agoI like the DoH initiative too. It's sad that Chrome doesn't support it for Linux yet and therefore Brave does not. HTTPS upgrade feature has always been there in Brave. Edit: I'm using system-wide DoT at the moment with CoreDNS but it doesn't work that well. Not sure why.
- new23d 6y agoFully support this argument and Mozilla's initiative. I work for a firewall co and we had taken a strategic decision to not allow plaintext traffic onto the internet (from cloud deployments). It's just lazy on the client or server operator's part to not have it so.
- cat199 6y agothis breaks caching of simple objects that do not require content security
- Deukhoofd 6y agoAs a developer I likely won't use this feature much, considering most of our internal development sites are http only. For the general public it might be useful though, especially the auto-upgrade feature, protecting them from the lazy network operators that didn't add a proper auto-redirect.
- conradludgate 6y agoAccording to another comment, you can still allow certain sites through http, so your Internet dev sites are still fine but the global sites will be blocked by default
- Deukhoofd 6y agoSure, but we have like 50 different internal domains for different customers, so that would get annoying real fast ;)
- ffpip 6y agoWell, you have to specifically enable this feature. So don't enable it.
- speedgoose 6y agoYou could use a self signed certificate.
- kevincox 6y ago
- whym 6y agoI wonder how it will work against websites like http://neverssl.com http://neverssl.com (which helps me to log in to some wifi portals, HTTPS Everywhere shows the prompt for a temporary exception.)
- mittermayr 6y agoAn alternative I use is http://captive.apple.com http://captive.apple.com (other OS vendors have their own). Which may have a higher chance of being detected by the portal (more likely to be white-listed) and triggering the prompt correctly.
- gspr 6y agohttp://detectportal.firefox.com/success.txt http://detectportal.firefox.com/success.txt is Mozilla's.
- stephen_g 6y agoFrustratingly it doesn’t always work that way - one I have seen that is just bizarre is Qantas inflight wifi. It actually allows captive.apple.com to bypass the captive portal, so your iPhone, iPad or Mac thinks it has internet access. So you try to navigate to a page or use an app and just hit HTTPS certificate errors! So you have to think of some other site that is only HTTP or get the information card and enter the address it tells you to log in! It’s crazy, because somebody must have had to configure something to explicitly let that through (not understanding the purpose of it?) and it just completely breaks it! I’ve tried to leave feedback (there is a link from the portal page) that they’ve screwed it up but it hadn't been fixed the last flight I went on..
- dspillett 6y agoPerhaps they were told to make Apple stuff work without login, and just blindly whitelisted all known Apple host address ranges.
- judge2020 6y agoIt might be forging responses from captive.apple.com and not actually sending those out to the internet. If you set up your own intercept that responds 'Success', iOS will assume it has internet as well.
- remedan 6y agoI just briefly played with it and there is an option to enable this mode globally and exclude specific sites (permanently or temporarily). Which is exactly what i needed.
- CodesInChaos 6y agoOne change I'd like to see in browsers is when the user enters a domain without protocol in the url bar it interprets that as https instead of http.
- gostsamo 6y agoThis is exactly the https mode.
- josephcsible 6y agoThe difference is what happens if you type http manually.
- jefftk 6y agoOr click on an http:// http:// link
- CodesInChaos 6y agoI don't think so. My proposed change only affects manually entered urls without protocol/schema. HTTP urls (entered manually or from links) would still work as expected, while https mode blocks them. I believe this change is small enough that they can make it the default, while http mode will likely remain optional for several years.
- joveian 6y agoThey can't make it the default yet without breaking a lot of things since a bunch of marketing people decided to break the security properties of TLS by using HTTP only vanity redirect domains. While I've found HTTP-only to be most common, sometimes these redirects do support HTTPS but hand out the main site certificate without updating it to include the vanity domain, resulting in a certificate error (however, this new built in HTTPS only gives you a HTTP warning in this case rather than a certificate error, unlike HTTPS Everywhere's EASE). Some sites also have HTTP only redirect from example.com to www.example.com.
- 6y ago
- abraxaz 6y agoGreat to see this built into firefox, I have been using HTTPS Everywhere https://www.eff.org/https-everywhere https://www.eff.org/https-everywhere to achieve similar results, it won't warn you if it is not https (i think) but it will try and upgrade to https if it can. It is available for chrome and firefox. What particularly annoyed me was using http to sites which supported https.
- AlexSW 6y agoFor me at least it warns me very blatantly and I have to asked to go to an insecure site if it's HTTP only. Perhaps we don't have the same configuration.
- akalsz 6y agoThat's not enabled by default, you first have to flip the "Encrypt All Sites Eligible" switch.
- jabl 6y agoIIRC HTTPS Everywhere works by having a whitelist of domains that are also accessible over https, and switches to https for those. So if a site isn't in the whitelist, it won't modify the request in any way.
- zapt02 6y agoHTTPS Everywhere will attempt to connect to a site using SSL, and if that times out will pop out an error message and allow you to load the site over HTTP temporarily. At least that's how it works on Firefox + latest version of the extension.
- cmeacham98 6y agoOnly if you have the "encrypt all elgible sites" option enabled, which is disabled by default.
- mxcrossb 6y ago
- y7 6y agoFinally! I've been waiting for HTTPS to be the default for a while now. From a security standpoint it's annoying that bar something like HSTS it's trivial for a man in the middle to force a downgrade to non-secure HTTP. The fix is to force yourself as a user to look for the lock symbol in the address bar, but that's terrible from a usability perspective. However, I'm not sure whether it'd be best to make this the mode the default for everyone. I imagine regular users would be quite scared/confused when encountering such a message, and that might lead to lots of valuable (mostly older) websites still running plain HTTP to be effectively cut off.
- kijin 6y agoThat's why it's important for features like this to be enabled in at least a couple of major browsers at roughly the same time. That way, users will blame the website operator instead of the browser when they suddenly can't access an insecure website.
- bbarnett 6y agoThe real and true bothersome part, is that Firefox (and others) do not seem to allow permanent exceptions. Going through multiple prompts, each and every time someone wants to do what they want, is problematic. I have gear on my LAN. No SSL, or self-signed, expired certs. I don't care. Ever. Why would I spent 10 seconds setting such things up? They're locked behind a firewall, (a secondary firewall), have no direct network access, and can't even be reached without port forwarding via SSH. Yet, do you think I can tell my browser "never ever prompt for this again"? Nope. Nada. I have zero issues with safer defaults, prompting when required. However, the idea that "Firefox knows best" is the sort of asinine behaviour that causes big tech issues all the time. My point is, this is going to be annoying... not because of the feature, but instead, if I enable it, I'll be cut off from legacy sites by a wall of forever "Do you want to really do this?" with likely 10 clicks of 'yes' and 'ok' and 'i understand', combined with never storing this as a default.
- solarkraft 6y agoWonderful, I'll definitely enable this! I'm pretty surprised it hasn't been a thing for years and isn't the default now.
- AntiImperialist 6y agoI have been using HTTPS Everywhere for many years: https://www.eff.org/https-everywhere https://www.eff.org/https-everywhere
- ffpip 6y agoYes, but one less extension with access to all your history, passwords and all other info.
- AntiImperialist 6y agoI'm not sure if I trust EFF any less than I trust Mozilla.
- aaplok 6y agoI am the same but in this case it is about trusting (EFF and Mozilla) more than Mozilla. You have to trust Mozilla either way.
- ffpip 6y agoI already trust Mozilla with everything. I do everything on my browser. It is always better to reduce extensions. I look forward to a day when I have nothing but uBlock Origin in my browser
- hpfr 6y agoWebExtensions have permissions and I doubt the EFF requests passwords and history for this extension. It’s also open-source, and although installing it from addons.mozilla.org could introduce some sort of MITM opportunity, as a recommended extension Mozilla puts it through a review process, so it’s about as tame as an extension this capable can get. But yes, it is always nice to reduce extensions installed.
- abdullahkhalids 6y agoI have been using HTTPS Everywhere since forever. Here are the permissions required: * Access browser tabs * Access browser activity during navigation * Access your data for all websites So can be pretty devastating if it went rogue, which I doubt.
- deleted 6y ago[deleted]
- m_eiman 6y agoIt's obvious I need to spend more time researching Gemini and similar things. The "web" is going to be a true monoculture very, very soon.
- dewey 6y agoUsing https is making the web a monoculture?
- jevgeni 6y agoIt obviously is. Having just an HTML site now becomes more expensive for no clear reason. Which makes more sense for people to check out Gemini.
- dewey 6y agoWhat makes it more expensive? A certificate is free (With LE or self-signed), the performance impact is negligible and there's a clear reason for why everyone should be using it.
- oofoe 6y agoIt does add a "tax" of sort in the form time or attention that must be paid to keep a website up. You can't just sling some files in a directory and be done -- you have to pay for certificates or pay (in time and executable capability) to keep LetsEncrypt up to date. And, as wonderful as LetsEncrypt is, it's not forever. At some point, they're gonna' get tired of messing with it or it will get taken over by private equity (see .org) and for whatever reason, it won't work any more. And sure, that's always been true, new stuff obsoletes old and things fall by the wayside. But my current browser can access modern websites as well as sites from the dawn of the Web. But FireFox 85, 87 or 90 will probably make https mandatory -- and that amazing continuity is gone.
- MaxBarraclough 6y agoThere are good reasons to insist on the use of HTTPS for all sites on the public web, with no exceptions or excuses. This topic has cropped up before: • https://news.ycombinator.com/item?id=21912817 https://news.ycombinator.com/item?id=21912817 • https://news.ycombinator.com/item?id=24640183 https://news.ycombinator.com/item?id=24640183 • https://news.ycombinator.com/item?id=22147858 https://news.ycombinator.com/item?id=22147858
- ffpip 6y agoI've used this for a few months now. It ugrades non-https connections on secure pages automatically. Very useful. Even big sites like microsoft, google images serve things over http dom.security.https_only_mode = true
- m4lvin 6y agoThanks for mentioning this! This about:config flag is also available in Firefox ESR 78 already (but there is no GUI for it yet).
- autoexec 6y agoAre there about:config entries to handle excluded sites?
- Hamuko 6y agoI tried this but I ran into a lot of issues so I just turned it off again. For example: Twitter would periodically refuse to load. You'd have to force refresh Twitter for it to load once again.
- ffpip 6y agoThe twitter problem is not related to this. Even I get it with this tweak disabled. It's definitely some other about:config tweak we have enabled.
- deleted 6y ago[deleted]
- deleted 6y ago[deleted]
- implying 6y agoThis is a great step, but I wish browsers would allow you to set domains that are considered to be secure origins in all cases. I have a decent intranet with transport security guaranteed by VPN, but because it isn't "HTTPS" I can't access tons of browser features.
- madjam002 6y agoIsn't this what HSTS does? Maybe a way to manually add domains to the list would be good.
- 1_player 6y agoI think GP is asking for a whitelist of HTTP-only domains the browser should consider safe.
- Vinnl 6y agoAccording to [1] you can disable this for individual sites. [1] https://news.ycombinator.com/item?id=25121929 https://news.ycombinator.com/item?id=25121929
- pimterry 6y agoIn Chrome/Chromium-based browsers, you do exactly that here: chrome://flags/#unsafely-treat-insecure-origin-as-secure
- zurn 6y agoHTTPS guarantees a higher level of security than "intranet", it works against on-path adversaries and provides end-to-end confidentiality & integrity & authenticity, plus provides forward security.
- sneak 6y agoThis is an important point: Modern TLS is often better crypto than most commonly deployed VPNs.
- tmsbrg 6y ago
- globular-toast 6y agoThere's a phenomenon I observe quite regularly in tech. A problem exists and creative people develop an innovative solution to said problem. The solution then becomes popular and a singular goal of uncreative people who deploy said solution everywhere and push it to its logical extreme. I remember seeing this in the mid-2000s when HTML tables were shunned in favour of "divs". I saw people reinventing tables using divs and CSS to display tabular data. Completely missing the point, of course. This is an example of that for me. How can I possibly trust every single website I visit? It means nothing to connect to a news website, say, and see the "green padlock". Who am I trusting exactly? That I've successfully connected to some load balancer that is operated by "super-trustworthy-tech-news.com"? What's the use in that? Am I supposed to trust them more than some man-in-the-middle just because they own a domain name? But maybe it's for privacy? If you want privacy you use tor. HTTPS does nothing for privacy when it's the same tech giant on the other end that is collecting all the data. It just means that said tech giant gets exclusive access to that data. Great. All this does is train people to not care about security and to just trust us to do the right thing because they are too stupid to get it. Sooner or later there will be an event where a government compromises a CA. Bad luck. Some Americans already decided this was a solved problem and that this could never happen.
- bambax 6y agoCouldn't agree more. Benefits of using HTTPS for most websites are doubtful, but the costs are real, in overhead and caching problems. We don't need the same level of security everywhere. (I'm not even sure we need that much "security" in general, but that's another topic.) It's sad to see Firefox continuing to bother itself with solving non-problems while serious bugs go uncorrected for years.
- rosstex 6y agoThis comment is why people make fun of HN.
- jacquesm 6y agoTables are better as well in the sense that they are a higher level representation than divs. The problem was that people were then using tables as a way to layout pages rather than to use them to display tabular data.
- antonyh 6y agoI'm for this. Any computer capable of running FF83 is powerful enough to use HTTPS everywhere. What it doesn't do, is force good TLS - there's nothing to stop a site using a weak algorithm, SSLv2/3, or old TLS versions. It also wrecks network-level caching using appliances like Squid.
- iso1631 6y ago> What it doesn't do, is force good TLS - there's nothing to stop a site using a weak algorithm, SSLv2/3, or old TLS versions. TLS 1.0 and 1.1 were disabled in Firefox 78 in June.
- antonyh 6y agoThat's good news. I know there was some flip-flopping over this because of covid and gov sites requiring old encryption. Great to hear that it's now done with.
- Cloudef 6y agohttp://n-gate.com/software/2017/07/12/0/ http://n-gate.com/software/2017/07/12/0/ This person won't be happy
- Jaruzel 6y agoawww crap - I've got loads of low-traffic websites that don't need https[1] that I'm now going to have to spend time sorting out certificates for. To be honest, it's about time that cert enablement is built into all web server configs (on all OSs) as a native feature instead of having to manually roll the config using this-weeks-currently-preferred letsencrypt script. --- [1] Yes, yes, I know everyone on HN prefers everything to be https, but out in the real world, most people don't care if all they are doing is browsing for information.
- abdusco 6y agoTake a look at Caddy server. Every site is configured for https by default with auto-renewed letsencrypt certificates. It even has an nginx-compatible configuration (but I think you'll like it's own (really simple) config more)
- Jaruzel 6y agoI'll check it out - cheers!
- glotgizmo 6y agoI route my domains through cloudflare for this reason. Just makes life easier for my <1k visitors/month sites.
- aurbano 6y agoIf you're ok with fronting your sites with Cloudflare you can get "fake" HTTPS by using the flexible option (HTTPS from the client to Cloudflare, and HTTP from them to your server) This satisfies the need to be on HTTPS, without actually having to change anything in your server. Not saying this is ideal, but for websites that don't _need_ it it could be the best/easiest approach.
- kevincox 6y agoIt doesn't completely block users from your site. It just makes them extra aware that any middleman will be able to see what they are reading, see anything they send and could possibly modify the traffic. If you are concerned about the power-users who enable this being aware of these facts then maybe you do need https after all. (Of course I suspect this mode will be made the default at some point, but that is probably at least a couple of years off.)
- simon_acca 6y agoIn case you are wondering what are the biggest websites that don’t do https by default: https://whynohttps.com/ https://whynohttps.com/
- dane-pgp 6y ago> Data last updated on 11 Jan 2020 at 23:51 UTC I wonder if that will get an update next January. I'd also be more interested in a list of popular sites that don't support HTTPS at all, i.e. the sites that will trigger a warning prompt under this new HTTPS-Only Mode.
- palominoz 6y agoI hope they aren't going to force users in https-only in the future. Software shouldn't cut off legacy content (old websites that aren't going to be upgraded with https) something just because in theory it is more secure. If someone is surfing the web as an adult he is responsible of himself. Other than this there are historical components (web firewalls) that aren't going to work anymore .. so security is a matter where it is an interest of someone (certificate sellers?)
- ainiriand 6y agoThe feature has an allow-list so you can configure your sites the way you want.
- palominoz 6y agoyes, my statement was "i hope they aren't going to force this for everyone in the future"
- shadowgovt 6y agoBecause browsers run code, they exist in that tricky space where some design decisions have to be made for the good of the commons. If you visit an HTTP site and get MITM'd, it's not just that the attacker can put you at risk by spoofing a credential input box; it's that the attacker can put third parties at risk by having your browser XMLHttpRequest as fast as it can at at someone else's site to try and DDOS them. At that point, the calculus shifts and we see a world where user-agent engineers have to make decisions like Microsoft did (to start forcing people to install security patches to the most popular OS on the planet, because we have enough evidence from human behavior to know that at some point, forcing-via-inconvenience becomes necessary). HTTP is fundamentally broken in that it can be abused to damage the network itself, and even though it's a deeply entrenched protocol, it's one that people have to be backing towards the exits on for that reason.
- palominoz 6y agoI think your comment goes specific, but i was talking generally. I don't really understand if you are arguing against my opinion.. I don't know what to respond.. bye
- toonies555 6y agocant wait to restart the browser when im in the middle of something important
- zajio1am 6y agoHot take: HTTPS-only mode is a bad idea if it is not paired with first-class support for self-signed certificates authorized using DANE+DNSSec. It just forces everyone to use broken/redundant CA model.
- acdha 6y agoCan you articulate precisely the problem you believe this will solve? From my perspective it seems like it’s just making the system more fragile and harder to fix since DNSSEC requires OS updates to improve, while not meaningfully preventing state-level attacks.
- topranks 6y agoThe current number of CAs does not prevent state-level attacks either. DNSSEC works I don’t really get that point. The “root of trust” problem is hard to solve. I kinda hear the DANE guys’ argument, I’d rather trust one authority than a thousand.
- acdha 6y ago> The current number of CAs does not prevent state-level attacks either. Right, so the question is why we should put a huge amount of effort into implementing and operating a system which doesn't make significant improvements. > DNSSEC works I don’t really get that point. It's mostly a layering question: if a new cryptographic algorithm is released or a problem with an old one comes out, browsers can update very quickly. Updating the operating systems and network hardware which implement DNSSEC takes considerably longer. DNSSEC lingered on 90s crypto for ages, key rotations were put off for years, etc. because everyone in this space has to be extremely conservative. That has security implications as well as delaying most attempts to improve performance or usability. Similarly, browsers can have extensive UI and custom validation logic for HTTPS. A lot of that information isn't present if you use DNSSEC without implementing your own resolver, so you get generic error messages and you don't get control over the policies set by your network administrator. This is especially interesting both as a risk if you don't trust your ISP or for dealing with compromises — if I compromise your DNS server and publish DNSSEC records with a long TTL, your users are at risk until you can get every ISP with a copy to purge the cached records ahead of schedule. All of those issues can be improved but it's not clear that there's enough benefit to be worthwhile. > The “root of trust” problem is hard to solve. I kinda hear the DANE guys’ argument, I’d rather trust one authority than a thousand. This is the best argument for DNSSEC but it's not clear to me how much difference it makes in practice when you're comparing the still nascent DNSSEC adoption to modern TLS + certificate transparency which also catches spoofing and is far more widely implemented.
- The_rationalist 6y agoWhy depreciating http in the long term? It should simply ask an annoying user confirmation that take all the screen. Removing my ability to visit the old web is pure nonsense
- crazypython 6y agoNot every web service is easy to set up with HTTPS as a simple Let's Encrypt service. Take a game. It dynamically balances between servers rented and destroyed on the fly. It needs a wildcard DNS certificate. Then all the sub-servers need to have that wildcard certificate. In conclusion, deprecating HTTP makes it harder for people to get started on the web. How are you going to get certificates for IP address' control dashboard, after all?
- wccrawford 6y agoA game absolutely should be use HTTPS anyhow, for their own security. But I'd say that anyone that has an operation so big that it dynamically creates and destroys servers to balance load should probably already be paying for their own wildcard cert anyhow.
- crazypython 6y ago> A game absolutely should be use HTTPS anyhow, for their own security. The game has no log-in or sign-up; no account system. The only potentially sensitive data sent is the nickname the user enters. > But I'd say that anyone that has an operation so big that it dynamically creates and destroys servers to balance load should probably already be paying for their own wildcard cert anyhow. The game is free and ad-supported. Dynamically creating and destroying servers is a basic requirement.
- imtringued 6y ago>It needs a wildcard DNS certificate. Then all the sub-servers need to have that wildcard certificate. Just give each server a separate domain and certificate as you create them. The matchmaking algorithm returns a url pointing to the server. >How are you going to get certificates for IP address' control dashboard, after all? By clicking the damn button?
- crazypython 6y ago> Just give each server a separate domain and certificate as you create them. The matchmaking algorithm returns a url pointing to the server. Do you mean a separate subdomain? (A separate domain would be very expensive.) I would need to figure out how to generate and provision certificates, in that case.
- app4soft 6y agoActually I'm using 3 browsers on my Linux PC: - Links2 (in graphics mode) — main, for fully no-JS browsing; - Pale Moon* (in Private mode) — main, for browsing w/ & w/o JS; - Firefox — for curious reasons if target website is not working in Links2 & Pale Moon. In last year I used Firefox maybe twice, as Links2 & Pale Moon. As for Android mobile: - Termux app + Links2 (in non-graphics mode) — main for fully no-JS browsing; - Prvacy Browser — main, for browsing w/ & w/o JS; - DuckDuckGo Browser — for curious reasons if target website is not working in Termux/Links2 & Privacy Browser. P.S. In conclusion, happy to see Firefox is still growing, but every release just brings many "hardcoded" features that, as for me, should not be "hardcoded" in free & open-source browser.
- pmlnr 6y agoHTTPS is brittle. HTTP is insecure, but will run forever. This move will literally kill the old web.
- nsomaru 6y agoI would hope you could expand on this a bit?
- bullen 6y agoNot OP but: HTTPS is not secure because it is centralized and it does not protect against MITM. HTTP is the foundation of our civilization, it will never go away how much certificate sellers try. But I would go one step further and point out that HTTP can be made secure manually selectively so that you only secure the things that need security! HTTPS wastes energy by encrypting cat pictures, and we don't have that much cheap energy left! But don't worry this will not kill HTTP only Mozilla/Chrome. Chromium will always allow adblockers for free and HTTP, because if they remove it, I'll fork it and add it back in, even if it takes 1 day to compile!
- MayeulC 6y agoTo me, HTTP is the wrong target. It would be much more interesting to replace IP, like Yggdrasil does (and I think gnunet, cjdns, hyperboria & others). If you IP is a cryptographic identifier: * It cannot be forged * Anyone can generate a new one on-demand * Every packet is authenticated, every packet can be encrypted * TLS becomes redundant However, the DNS part remains a hard one. How to securely link to websites you have never seen? Pet names seem like a way to do so. Asking users to type IP addresses isn't really an answer, I think, but I don't know if there's a lot of "basic" users who type URLs in nowadays, they all seem to rely on google providing the right website anyway, or the web browser itself. It's not like DNS is also our single source of trust nowadays, but at least certificate providers are competent enough to make sure names are resolved correctly. One option would be to make signed DNS records over a DHT: the root authority "." signs "com", "net", etc, that sign "ycombinator", etc. Publish to DHT, hash-indexed. Of course, point-to-point connections have their weaknesses as well, it might be interesting to migrate to something like beaker browser (html on top of hypercore, formerly DAT, kind of like mutable torrents in a DHT). At the end of the day, the core issue is: migrating users is difficult if the benefits are not immediately obvious. And yes, massively adopting anything else would litterally "kill the old web", in the protocol sense. In the community or content sense? Not so sure. https://yggdrasil-network.github.io/ https://yggdrasil-network.github.io/ https://gnunet.org/en/ https://gnunet.org/en/ https://github.com/cjdelisle/cjdns/ https://github.com/cjdelisle/cjdns/ https://beakerbrowser.com/ https://beakerbrowser.com/ https://hypercore-protocol.org/ https://hypercore-protocol.org/
- Szel 6y agoHave been using HTTPS Everywhere from some time. The worst are sites which have https but not configured properly - cert for wrong domain or expired.
- imtringued 6y agoAs long as there is an escape hatch this is great. I absolutely loathe having to setup http to https redirects because it means the first visit for many users is completely unsecured. HSTS preloading is a hack. Why not just connect to https first?
- peterwwillis 6y agoA long time ago I suggested a new uri prefix - "secure://" - that would be a synonym for "HTTPS-only". If you visit a secure:// link, every single page load in the session would require strong encryption, secure cookies, etc. The idea was to allow http if needed, and alternately allow strict https if needed, in a backwards compatible way (visiting a https:// https:// url would work as before, but visiting secure:// would trigger the strict security for the rest of the session). This way you have the best of both worlds and the user (and server) get choice/agency. The purpose was to stop MITM. The ability to MITM only requires blocking port 443 and letting the browser fall back to 80; this works even against HSTS because most people will just try other URLs until one works. So you need a way to avoid MITM at least for some specific requests. Banks, e-mail providers, etc would say "type in secure://mybank.com in your browser for strong security". Another option was a "secure only" button on the browser. It seems they're moving towards this. They've buried it in preferences, which hopefully they'll change to the front UI. But I still think the secure:// links are easier for laypeople.
- MayeulC 6y agoA lot of things should be better in theory, like adopting PAKE schemes (like "OPAQUE") that could perform a two-way authentication and key negociation over an insecure connection by just displaying a login prompt. As always, the issue is adoption. What good is a solution if no browsers implement it? Catch-22, which is usually broken when a giant (google nowadays) decides to break it. And they need incentives to do so. Which is why we need the non-profit Mozilla giant. badly. https://en.wikipedia.org/wiki/Password-authenticated_key_agreement https://en.wikipedia.org/wiki/Password-authenticated_key_agr... https://news.ycombinator.com/item?id=18259393 https://news.ycombinator.com/item?id=18259393 https://tools.ietf.org/html/draft-krawczyk-cfrg-opaque-06 https://tools.ietf.org/html/draft-krawczyk-cfrg-opaque-06
- blackrock 6y agoThe Firefox versioning numbers are lost on me. I have no idea of the importance between 83 vs 80.
- ChrisSD 6y ago83 - 80 = 3 Therefore version 83 is 3 versions ahead of version 80. Note that "version" in this context is shorthand for "major version". It does not include minor patches that only fix a bug or security issue. Each new major version of Firefox comes with new features and may occasionally deprecate or remove old features. They are currently released roughly every 4 weeks.
- newscracker 6y ago> In summary, HTTPS-Only Mode is the future of web browsing! It has certainly seemed like HTTPS is the future of the web for the last few years. I love this HTTPS-Only mode and wish it would become the default (with better downgrades and messages for users who may not understand what it means). With the number of HTTP-only sites dwindling, this could result in a faster experience for sites that do not want to (or haven’t figured out how to) use HSTS or HSTS Preload (no redirects from HTTP to HTTPS) and for users who haven’t heard of the HTTPS Everywhere [1] extension. [1]: https://www.eff.org/https-everywhere https://www.eff.org/https-everywhere
- bsradcliffe 6y agoThis is great and all--and cheers to HTTPS Everywhere fans throughout this thread, but none of you are answering the question "can I uninstall HTTPS Everywhere now as a result of this feature shipping?"
- joveian 6y agoDo you want the most HTTPS connections you can get with almost no chance of inconvenience? Then use HTTPS Everywhere in the default mode. If you don't mind seeing that you are about to connect to a HTTP site and click ok if you want to contine then yes, you can get rid of HTTPS Everywhere. In this case you will get occaional shocks like "Why is my bank's website giving me a HTTP only warning? Oh, it is because there is a HTTP only redirect to the www domain."
- at_a_remove 6y agoOnce this sort of thing is widely accepted, we'll see various blogs and websites silenced by having a certificate revoked. Not right away but soon enough. It's a very exciting development. It's managed to use the geek "Everything has to be like this!" fanaticism to drag in a mechanism of control. I wonder which of the Four Horsemen it will be used against first.
- josephcsible 6y agoThere's a ton of trusted roots across multiple countries. I think the odds are virtually nil that none of them would let you have a certificate.
- maxk42 6y agoCertain governments already require their root beer the only one trusted by software in their country.
- josephcsible 6y agoWhich governments and which software?
- einpoklum 6y agoThis is a "rewriting reality to fit our agenda" kind of a post. > The majority of websites already support HTTPS When I run a webserver on a machine I just set up, it has no certificate, certainly not one signed by anybody else, and there's no reason I need to be forced to use encryption with it. > and those that don’t are increasingly uncommon. False. Although - for fashionable Silicon Valley companies, "most websites" probably means something like Facebook, Google, Amazon, Wikipedia and a few others. > Regrettably, websites often fall back to using the insecure and outdated HTTP protocol. HTTP is "outdated"? "Fall back"? ... Seriously? I guess we're just lucky FF's share has dropped so far that we shouldn't worry about this stuff. I just hope other browsers don't do this (although - who knows, right?)
- jillesvangurp 6y agoGood feature in general. A few old sites that will get a bit more annoying to use because that fact is now pointed out to the user. But otherwise no impact for users. I hope it does not get too annoying for backend developers for running things locally because locally you typically don't set up https.
- nashashmi 6y agoHow many people actually understand what securities HTTPS provides. I remember clicking through them not knowing what they meant or thinking there was nothing I can do about it. Or thinking no one REALLY can snoop except in theory. And that is the problem. HTTPS messages need to reform. How about “the website and its data is observable and can be spied on by a third party along the network. Please be careful when entering data.”
- testHNac 6y agoFirefox is my primary browser on desktop and Mobile. On Windows 10, I use Cold Turkey to block distracting websites. I often have issues with Firefox bypassing the blocks on Windows, ignoring the Hosts settings. On Android, Block Site addons are not compatible with the new Firefox for Android. I love Firefox, but some recent changes make me feel that I have less control over my browsing experience. I hope they don't make things 'default' for our 'protection', rather leave some things to the user to decide as per their preferences.
- oliveiracwb 6y agoWhere you see security, I see control. A way to commoditize the launch of ideas and information. Maybe 30 years from now, they will not prohibit any type of communication that is not properly licensed and standardized. As they do with commercial imports and exports. In Brazil today when you buy a product from another state of the federation, the tax goes partly to the origin of the product shipped and partly to the destination where it is purchased.
- StavrosK 6y agoHow does that commoditize the launch of ideas and information?
- crazypython 6y agoWhen enabled, it forces a domain to be signed by a CA to be displayed. Effectively giving the CA a veto over the content.
- StavrosK 6y agoI guess, but only in the way your power provider has veto over the content. The CA doesn't care about the content, only about you proving that you own the domain.
- crazypython 6y agoLike CAs, the power company can be controlled by the government. Let's say governments ban youtube-dl. The prosecution gets a court order to order CAs to not renew youtube-dl.org. If they're using a Let's Encrypt style 30 day certificate, youtube-dl has 30 days to comply or be soft-banned from the internet.
- StavrosK 6y agoWhy go to the CA when they can just order the domain itself to be shut down? If there's a court order against you, your site being HTTP won't save you.
- tyingq 6y agoI do worry about the sort of monoculture with Let's Encrypt. A second and third provider that do the same thing would reduce the blast radius for potential outages. Grateful for LE, but there's a lot riding on it. Similar for Cloudflare.
- iso1631 6y agoYes, LE goes boom for some reason, and there's at most 30 days to get a working replacement online before server certificates start failing. I'll try to keep my tin hat stored.
- anaganisk 6y agoOr just a day, if people wait till the deadline
- jsmith45 6y agoI see at least two other ACME based Free CA services: https://www.buypass.com/ssl/products/acme https://www.buypass.com/ssl/products/acme This one appears fully drop in compatible with LE, except that it does not offer wildcards. https://zerossl.com/ https://zerossl.com/ Does offer wildcards, but slightly less compatible, because you need to sign up with a web form, and provide your credentials via the optional ACME EAB feature (External Account Binding), so not all tooling will support it.
- makecheck 6y agoUpon launch, Firefox 83 displays essentially a full-page ad for Pocket, with a tiny link at the bottom (have to scroll to it) to get the release notes for “what else” is new in Firefox. So all kinds of significant enhancements in 83, including HTTPS mode, might essentially be missed by most users. (Heck, I only knew because of this HN post.) Why do programs insist on “hijacking” things? Release notes seem particularly vulnerable to this, e.g. iPhone apps love to have “notes” that don’t actually tell you anything at all, just marketing-speak.
- aeturnum 6y agoLike others, I'm not exactly inspired by this feature. I'm an advocate for HTTPS-everywhere, but I think we're quickly moving past the point of usefulness for most people. On a personal level, as a developer, I actually find the ban on mixed connections on a web page much more frustrating. It's easy for me to get a cert for nginx for my side project. It's another thing entirely to figure out how to give my application server access to the certs in the "right" way so that the application can terminate wss:// connections. I have to figure it out, of course, because firefox will refuse to connect a ws:// connection on a https page.
- vbezhenar 6y agoI don't understand your problem. Nginx should proxy all connections including websocket ones. Just don't expose your application server and use nginx as a reverse proxy.
- aeturnum 6y agoI don't understand my problem either - if I did it wouldn't be a problem! I'm not here fishing for tech support, but this is a real thing I'm encountering and I don't know that expressing disbelief feels productive? The point I'm trying to express is that giving a cert to your webserver is often only the first step in a relatively complicated process of securing all you assets. I wish browser makers would ask about blocking insecure connections instead of doing it by default. If you're interested in the kind of thing I mean see below: ------------------------------------------------------------------------------------------ So, for example - I'm running a quart server on hypercorn for a side project. Just giving nginx the certs will not, for reasons I don't understand, allow a wss:// connection to successfully connect (returns a 400). The developer conversation around this[1] suggests giving the certs to the application server. I can confirm that this works, but again I don't understand why. [1] https://gitlab.com/pgjones/quart/-/issues/319 https://gitlab.com/pgjones/quart/-/issues/319
- vbezhenar 6y agoIt could be because Host header supplied by nginx to your appserver by default will be something like 127.0.0.1 instead of yourwebsite.com.
- kazinator 6y agoWhat I don't understand is why there isn't a simple button when you land into a HTTP page to switch to HTTPS. In the browser bar, to the left the address, you get an icon of a padlock, with a red slashed circle across it, and the word "Not secure". Why can't you click on this to get a popup to switch to trying the HTTPS version of the URL? You can click on it, you get to a read-only tree of information providing info about the site. If you right click on it, you get a context menu popup about customizing the toolbar.
- minitech 6y agoBecause that’s a lot of hidden UI for something people rarely want to do (be on an insecure version of a website while a secure version exists) and might not work and that they can still do relatively easily by typing ”s”.
- kazinator 6y agoThe lot of hidden UI is already there; all it needs is one menu command. There is UI for printing a page; I'm pretty sure I've adjusted a HTTP to HTTPS more times than I've printed a web page. > still do relatively easily by typing ”s”. You have to position the cursor first; it's annoying.
- TurkishPoptart 6y agoIs HTTP (without the S) only risky if you're transmitting data, and not just browsing?
- ghayes 6y agoAn insecure connection can be trivially eavesdropped (e.g. by your network peers, router, ISP or intermediate hops). Much of the time this will include identifying information such as your IP address and browser cookies. Consider reading medical publications or other personal topics and having that logged by an unrelated third-party. TLS adds significant privacy to your browsing habits, even when not transmitting data, per se. Edit: and, as others have said, the content can be modified by a man-in-the-middle attacker, which can inject fake content or malware.
- bobbylarrybobby 6y agoNo, you're still susceptible to MITM attacks. I could imagine an election info site, that said the election was November 3, being MITM'd by an adversary who changed the page to say November 4, causing many voters to miss the election by a day.
- egberts1 6y agoThis is why you block DNS selectively at your local gateway AND host a DNS resolver there as well while blocking ALL DNS except to your gateway. Web browsers have no business using DNS over HTTPS, none; nada. zip. We've opened a can-of-worms ... for malwares to evade further network detection ... effectively with DNS-over-HTTPS.
- ajyey 6y ago"When Firefox autocompletes the URL of one of your search engines, you can now search with that engine directly in the address bar by selecting the shortcut in the address bar results." This is what I've been missing from chrome!
- strifey 6y agoOh wow, this is huge! Ever since switching back to FF, I constantly forget what my "shorthand" shortcut is for my custom search engines.
- pengaru 6y agoIs there any concern for how much power LetsEncrypt holds over large swaths of the internet in a world where browsers refuse to connect using HTTP? What prevents LetsEncrypt from censoring entire domains by refusing to renew their short-lived certificate?
- kccqzy 6y agoJust switch to a different provider for your certs. The startup I previously worked for switched from LetsEncrypt to AWS-provided certificates since we were already using their ALBs.
- meerita 6y agoMy blog doesn't have cookies, javascript, forms, no server-side, just html files, why should I go with https to avoid this discriminatory treatment?
- Xavdidtheshadow 6y agoYou ensure that the content you serve is exactly what arrives on the reader's machine. The most prominent example is ISPs inject ads or messages. Search for "comcast injecting ads" to see some examples.
- julienb_sea 6y agoThere are a lot of confusing comments in here. Maybe I'm in the minority but I use chrome, which seems to default convert to https on any site that supports it, and will provide visible warnings when the site doesn't support https. Also man in the middle attacks seem massively overblown. If you are sitting at home on your private network, the likelihood of a man in the middle attack is stunningly small, such that it's completely irrelevant - especially in regards to the likely trivial content being viewed over http.
- jjav 6y ago"we expect it will be possible for web browsers to deprecate HTTP connections and require HTTPS for all websites" Thinks about the implications of this. It will be impossible to host any web content unless you get blessed by a well-known CA (packaged in the platform/browser CA store). That's why we have Let's Encrypt, right? Yes, thanks to them. Now imagine a future where Let's Encrypt goes away, for whatever reason. Now it's impossible to host any web content without getting approved by a commercial CA.
- makecheck 6y agoOne thing I’ve noticed in HTTPS mode is that sites where I used to lazily type "foobar.com" (resolving to "www.foobar.com" over HTTPS) do not necessarily auto-direct anymore, instead displaying the scary message first. Whereas, typing "www.foobar.com" directly does not trigger the message. I’m not sure where the auto-switch from "foobar.com" to "www.foobar.com" occurs; if it’s in the browser, ideally Firefox would attempt this auto-correct first and try the HTTPS connection to the corrected location, to minimize the chance of triggering a warning.
- Ajedi32 6y agoThe redirect gets sent by the server. foobar.com and www.foobar.com are technically different domains, even if conventionally one should always redirect to the other.