7 ms·
They support SSL because some browsers force https, but they then force a redirect to a non-SSL page. Seems reasonable. I think I may be missing the point of th
by saila 3y ago
They support SSL because some browsers force https, but they then force a redirect to a non-SSL page. Seems reasonable. I think I may be missing the point of this being posted on HN. Does it cause issues in certain workflows or something?
- paxys 3y agoNope, people are just looking for their daily dose of outrage.
- rubatuga 3y agoWhich browsers force https when you type in http:// http:// before the domain?
- Linux-Fan 3y agoFirefox 102.10.0esr seems to do this here. I type into the address bar: `http://example.com http://example.com` and it corrects it to the HTTPS version. Even when I try to change the URL back to the `http:// http://` it goes to the HTTPS version. When I try the same with curl as in `curl -v http://example.com http://example.com` I can see the HTTP traffic coming through correctly i.e. the site still supports HTTP. Note that I have configured "Don't enable HTTPS-Only Mode" in the Firefox settings. I use some addons although none to specifically redirect my requests to HTTPS...
- cuteboy19 3y agoIs it possible that example com is redirecting you
- sohkamyung 3y agoI am using Firefox Nightly 114.0a1, with "Don't enable HTTPS-Only Mode" enabled, and a visit to http://example.com http://example.com works as expected (a GET from http). Enable the web developer tools (Menu->More Tools->Web Developer Tools), visit the site again, and see if it is directly visiting the site or getting a redirect.
- Linux-Fan 3y agoThe developer tools Network tab directly indicates the first connection as being HTTPS. No redirect shown there. I additionally tested with my own site: http://masysma.net/31/web_main.xhtml http://masysma.net/31/web_main.xhtml. It is configured to not redirect to HTTPS except for the root node (http://masysma.net http://masysma.net). It is not configured to behave any differently for user agents and hence the redirection (or no redirection) behaviour can also be checked by the commandline tools that print the course of the redirection (like curl, wget).
- deleted 3y ago[deleted]
- iudqnolq 3y agoChrome, in an experiment they've rolled out to half their users in preparation of making it the default. https://chromium.googlesource.com/chromium/src/+/19719792bbd02433d8aeb7fda7fb00fc8ab7f0a6/chrome/browser/ssl/https_upgrades_interceptor.cc#66 https://chromium.googlesource.com/chromium/src/+/19719792bbd... Regardless, the point of neverssl.com is that a non-technical user can learn "if I'm on a new wifi network and I see errors when I try to visit pages I can enter neverssl.com and get to the wifi login". Adding ssl + a redirect is much easier and more effective than trying to retrain everybody to manually type http. It probably should have been named wifilogin.com or something. But renaming it has the same retraining issue.
- zamnos 3y agoIt's the dichotomy between the name, neverSSL, and the fact that it's now doing SSL, that makes it interesting, because the name and proclamation is no longer accurate. Also it was hotly discussed yesterday so there's points for this story reflected from that.
- hammyhavoc 3y agoWait until people hear about a popular sex act and it being a misnomer.