3 ms·
HTTPS-only mode doesn't do the initial HTTP request if HTTPS is available. This prevents downgrade attacks, prevents leaking private information such as the ent
by Sayrus 1y ago
HTTPS-only mode doesn't do the initial HTTP request if HTTPS is available. This prevents downgrade attacks, prevents leaking private information such as the entire URLs (many email tracking links default to HTTP so you leak the token contained in there) or if the website supports it even the domain name you access.
It's not "needed", sometimes it breaks things (HTTP-only website but with HTTPS port opened), sometimes it fixes things (HTTPS-only website with HTTP-port opened).