Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

What scaring? Chrome shows a gray "not secure" and firefox has a crossed out padlock. That seems understated to me.

If you're talking about certificate error pages, then yeah there's room for improvement. Not every site needs the same level of warning there. But caution makes sense as a default. Something went wrong.



My Chrome does not allow me to visit HTTP page. Yours will do the same soon.


Why doesn't yours? What do you mean by "soon"?

I just tried http://example.com/ in chrome canary and it's the same.

Edit: Okay, I found the "Always use secure connections" setting, but that has been around for a while. And it doesn't actually stop me, it asks.

Also downloads are or will be blocked on http but that's not too bad of an idea.


An invalid certificate also doesn't technically stops you and just asks if you really want to proceed.

By "soon" I mean that this particular behavior surely will be the default one. Here's old blog post: https://blog.chromium.org/2021/03/a-safer-default-for-naviga...

And quote from it: "HTTPS protects users by encrypting traffic sent over the network, so that sensitive information users enter on websites cannot be intercepted or modified by attackers or eavesdroppers. Chrome is invested in ensuring that HTTPS is the default protocol for the web, and this change is one more step towards ensuring Chrome always uses secure connections by default."

I think that the direction is obvious.


Any browser that actively prevents viewing an HTTP site is not fit for purpose. Set secure defaults, absolutely. Show scary warning pages if you insist. But don't prevent legitimate activity entirely.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: