4 ms·
My main takeaway from this article is that the correct way to support older systems is not by supporting older versions of SSL/TLS. It is better to add support
by charsi 6y ago
My main takeaway from this article is that the correct way to support older systems is not by supporting older versions of SSL/TLS. It is better to add support for plain HTTP delivery and only support modern SSL/TLS variants. Since the author recommends upgrading anyone with 'Upgrade-Insecure-Requests' header I don't think there is a downside to doing this.
If you truly don't have legacy clients trying to visit your website then 99%+ visitors won't see any difference in behaviour. So no reason NOT to do this.
- Ayesh 6y agoThere are many downsides. First, a response without the redirect is still a "successful" request. This easily allows a middle man to observe and modify the response and request. With a 301 redirect, the server is not sending any html/json/etc content to the server - just the header. Search engines, HTTP caches, bookmark managers, etc they all accept and update their indices upon 301 redirects. Non-browser user agents are unlikely to read and interpret CSP headers. I am firmly set that these older user agents without SSL support, or ones with old vulnerable implementations are not worth supporting. You are taking the security level of everyone down, just to support that likely minority. They are already having problems with several other sites. They upgrading their hardware/software is the easier compromise to make, compared to the web site lowering the security for everyone.
- charsi 6y ago> This easily allows a middle man to observe and modify the response and request. The article is aimed at personal websites and blogs where security is not a significant concern. Whats the downside of search engines and bookmark managers using the HTTP url ? Users who visit the link will get upgraded anyway.