4 ms·
> There's still a fairly large amount of web servers that do not talk https, and you simply cannot assume that they do. OTOH I'm browsing since years forcing H
by TacticalCoder 2y ago
> There's still a fairly large amount of web servers that do not talk https, and you simply cannot assume that they do.
OTOH I'm browsing since years forcing HTTPS only and life goes on fine. If the absolute worse comes to worse, I can use archive.is or archive.org but it's very rare that I need that.
Basically: if a link is HTTP to me it's not worth opening.
The one exception would be Debian packages URLs: but these are signed and the signatures are verified.
User _apt is the only one allowed to emit HTTP traffic.
This prevents my ISP or anyone else injecting nasty stuff.
- forgotmypw17 2y agoJust because it is accessible to you does not mean it is accessible to everyone else. HTTPS has many failure modes which make it unreliable for essential access, such as time mismatches, certificate expirations, ssl version mismatches, etc. Security and privacy are important, and they are also not absolute. Sometimes the risk is outweighed by the importance of being able to access essential resources and reading material.
- Analemma_ 2y agoUser preferences should not be encoded into parser behavior, that’s nuts. You wouldn’t just arbitrarily change an ftp:// link to an imap:// link, so why would you accept it here? That exists at a whole other layer of the stack.
- dmd 2y agoThey would arbitrarily change an ftp:// link to an sftp:// link and then complain that it didn't work.