5 ms·
To get this through what you have to do is a) create a Chrome clone that rejects third-party scripts and has other security enhancements by default (do browser
by david_draco 5y ago
To get this through what you have to do is
a) create a Chrome clone that rejects third-party scripts and has other security enhancements by default (do browsers really still need http support?). Then, you can say "Your site doesn't work with SuperChrome!" and shame until they fix it, to reach also the SuperChrome users (hopefully growing in number). SuperChrome cannot be a loose set of extensions, it has to be a well-defined thing.
b) have other services treat sites preferentially: higher throughput, better caching, higher ranking in search results, better user retention. I think this can easily be achieved, because the load-time will be shorter on such sites, therefore users will stay longer, and faster sites are already preferred by Google. This is the "AMP route" btw.
- jtbayly 5y agoYes. Browsers really should maintain HTTP support. There’s no reason to require every static site in the world to be encrypted in transit. And in particular, there’s no reason to block off all the actual good websites that are old static sites still serving their purpose.
- wayoutthere 5y agoStick an SSL proxy in front of them and be done with it. This was a solved problem 15 years ago.
- sneak 5y ago> There’s no reason to require every static site in the world to be encrypted in transit. Yes, there is. Encryption doesn't just provide privacy, it also provides authentication. Being able to tamper with downloadable code (i.e. javascript) in transit is a nonstarter. Everything needs to be authenticated, and the way we authenticate data from a webserver in 2021 is by using TLS. Ban port 80.
- phil294 5y agoHere [1] is an interesting article that advocates for not blindly enforcing SSL everywhere as it makes deliberate mitm caching impossible. Also discussed in 2018 [2] [1] https://meyerweb.com/eric/thoughts/2018/08/07/securing-sites-made-them-less-accessible/ https://meyerweb.com/eric/thoughts/2018/08/07/securing-sites... [2] https://news.ycombinator.com/item?id=17707187 https://news.ycombinator.com/item?id=17707187
- Ntrails 5y ago> do browsers really still need http support? There are some legitimate resources I use that are http only (eg the Dungeon Crawl Stone Soup wiki). I turned Firefox over to auto-error/alert on http, and it bugs me every time I go there