Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Ah yes! It's HTTPS Everywhere. Thanks.


Does HTTPS Everywhere just blindly redirect you to an HTTPS equivalent? That's crazy! (As you're finding out) there's absolutely no requirement that a site that responds to HTTP will also respond to HTTPS, or will respond with the same page even! Could be completely unrelated content. Could be controlled by a different party!


By default HTTPS Everywhere falls quite far short of "everywhere". It just has a list of things to try, where there's a popular site often linked to by HTTP for which HTTPS exists. It even handles cases where the sites have different server names e.g. https://secure.example.com versus http://www.example.com which was a big trend at maybe the turn of the century.

So, if you want more you ask it to instead try to upgrade everything, by simply replacing http-> https.

I don't use HTTPS Everywhere, but, I do run Firefox. Firefox includes a feature called "HTTPS Only Mode" which is default off for now. In HTTPS Only Mode (which you can enable for Private Browsing, if you just want to ensure your porn doesn't get swapped for Rick Astley; or for all tabs if you like me would prefer unencrypted HTTP to go away now please) Firefox behaves as follows for all URLs whether you typed them in, clicked a link on a page, or in an email, or whatever:

* If rewriting http as https "just works", that's what it does. Yes, in theory https://pig.example/ could be a site about pork farming while http://pig.example/ is a site about how awful the police are, but nobody actually does that on purpose unless they're being deliberately contrary - so there's no reason to care about it.

* If the HTTPS site does not exist, Firefox tells you there is no secure site available, it says the most likely reason is mundane - there is no secure site, but it's possible something nefarious is happening. One click takes you to the HTTP site you originally were linked to.

* If the HTTPS site "exists" only in the sense that if you typed that HTTPS URL in manually it would give an error on another browser (or indeed Firefox) that counts as not existing for this purpose. e.g. bad certificate, terrible SSL configuration, somebody doesn't understand how ports work.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: