4 ms·
Another problem here is the initial HTTP request on the web, if the site isn't in the HSTS preload list. It's easy for this to happen when you click a link, and
by sayrer 5y ago
Another problem here is the initial HTTP request on the web, if the site isn't in the HSTS preload list. It's easy for this to happen when you click a link, and there are lots of HTTP links generated by protocol-less highlighting too (think foo.com with no prefix).
What usually happens these days is a redirect to the HTTPS site, but that first request can still be attacked.
- mcculley 5y agoI find that many sites implement HSTS and the redirect to HTTPS wrong. For example, they will have http://example.com http://example.com redirect to https://www.example.com https://www.example.com instead of first redirecting to https://example.com https://example.com. According to the spec, the browser will not automatically upgrade to HTTPS next time, leaving that first request still open to attack. [Kind of a plug: I made a test for this in my tool, DomainProactive (https://domainproactive.com https://domainproactive.com). I would appreciate feedback on this kind of error.]
- boring_twenties 5y agoIndeed. I now have firefox configured to always try HTTPS first. A warning pops up if it doesn't work, and you have to click through it if you want to proceed. It turns out that a large number of sites not only have http://example.com http://example.com redirect to https://www.example.com https://www.example.com, as you describe, but https://example.com https://example.com doesn't work at all -- resulting in this warning. Clicking through it, you end up at https://www.example.com https://www.example.com.
- LinAGKar 5y agoUnless you enable HTTPS-only mode, or HTTPS Everywhere EASE mode.
- zeepzeep 5y ago> HTTPS-only mode should be the default.
- escalt 5y agoExactly. A commonly missed attack vector is just intercepting plaintext http and blocking https, so the browser thinks the site doesn't offer https and will just continue in plaintext. The same criticism applies to smtp using starttls, an attacker can suppress the starttls command and the default is to just continue in plaintext. This is why an https only mode is important. In Firefox it can be enabled somewhere in the settings.
- cxcorp 5y agoLuckily browsers are nowadays shifting towards making the initial request via HTTPS. Chrome, for example, has been using HTTPS when typing an address into the address bar without specifying http:// http:// explicitly [1]. [1]: https://blog.chromium.org/2021/03/a-safer-default-for-navigation-https.html https://blog.chromium.org/2021/03/a-safer-default-for-naviga...
- z3t4 5y agono, it will relay your URL via Google Search :P