4 ms·
Yes, I suppose that might work at least some of the time. Most browsers these days, however, would send you to the https site simply because you had visited it
by aptwebapps 12y ago
Yes, I suppose that might work at least some of the time. Most browsers these days, however, would send you to the https site simply because you had visited it more frequently unless you typed out the full url and managed not to select the offered completion.
- callahad 12y ago> Most browsers these days, however, would send you to the https site simply because you had visited it more frequently Actually, in that case, modern browsers would completely refuse to send you to the http site, even if you typed it in explicitly. All thanks to Facebook's 90 day HSTS header [0]. They could improve their security further by getting Facebook into the Chromium preload list. That list, which is shared with Firefox, eliminates the need for an initial, clear connection. [0]: https://en.wikipedia.org/wiki/HTTP_Strict_Transport_Security https://en.wikipedia.org/wiki/HTTP_Strict_Transport_Security [1]: https://src.chromium.org/viewvc/chrome/trunk/src/net/http/transport_security_state_static.json https://src.chromium.org/viewvc/chrome/trunk/src/net/http/tr...