4 ms·
I hope they aren't going to force users in https-only in the future. Software shouldn't cut off legacy content (old websites that aren't going to be upgraded wi
by palominoz 6y ago
I hope they aren't going to force users in https-only in the future. Software shouldn't cut off legacy content (old websites that aren't going to be upgraded with https) something just because in theory it is more secure. If someone is surfing the web as an adult he is responsible of himself.
Other than this there are historical components (web firewalls) that aren't going to work anymore .. so security is a matter where it is an interest of someone (certificate sellers?)
- ainiriand 6y agoThe feature has an allow-list so you can configure your sites the way you want.
- palominoz 6y agoyes, my statement was "i hope they aren't going to force this for everyone in the future"
- shadowgovt 6y agoBecause browsers run code, they exist in that tricky space where some design decisions have to be made for the good of the commons. If you visit an HTTP site and get MITM'd, it's not just that the attacker can put you at risk by spoofing a credential input box; it's that the attacker can put third parties at risk by having your browser XMLHttpRequest as fast as it can at at someone else's site to try and DDOS them. At that point, the calculus shifts and we see a world where user-agent engineers have to make decisions like Microsoft did (to start forcing people to install security patches to the most popular OS on the planet, because we have enough evidence from human behavior to know that at some point, forcing-via-inconvenience becomes necessary). HTTP is fundamentally broken in that it can be abused to damage the network itself, and even though it's a deeply entrenched protocol, it's one that people have to be backing towards the exits on for that reason.
- palominoz 6y agoI think your comment goes specific, but i was talking generally. I don't really understand if you are arguing against my opinion.. I don't know what to respond.. bye