4 ms·
No, that's not a good idea, there are lots of cases where the static page being sent to you contains secret information, and should yell loudly when the source
by coderzach 11y ago
No, that's not a good idea, there are lots of cases where the static page being sent to you contains secret information, and should yell loudly when the source can't be verified. Secret information that you don't want to be intercepted or modified by an attacker.
- _yosefk 11y agoSure, but there are also plenty of cases where you don't care. Why make everyone everywhere bother with HTTPS? If you want to protect the user, as a browser, go ahead and yell or block access, but only when the user's data is at risk. Blocking access to my page because someone might have misrepresented what I put there, and thus forcing me to deal with HTTPS? That's more than a little excessive IMO.