“When users use a private window in Firefox, the connection to the requested domain will now default to HTTPS even if a user manually enters the HTTP protocol” zdnet.com/article/firefo…
Firefox 91 in private mode after attempting to load a site over the insecure scheme that refuses to do HTTPS. Welcome to the future, I like this 😊
Note that you can still access the site - nobody has killed HTTP here - you're just warned about there not being a secure connection. You can still decide to load it and take the chance.
Responses along the lines of "but I'm the master and if I tell the browser to load a page over HTTP then I damn well expect to be insecure" are *really* short-sighted. Here's why:
There are over 4 billion people on the internet. With the exception of those holding this view (and there's a sub-1% number of you), everyone who types in a URL - including the scheme - just wants to load the page. They don't think twice about TLS.
If they type in "http://[url]" it's not because they're consciously thinking "gee I'd like to load a site without without needing a valid cert", it'd because they're thinking "just give me the damn website". Defaulting to HTTPS is just one more way of protecting the masses.
If you're in that sub-1% of people and you'd like to be able to force insecure requests, then just disable the feature. It'll take you 1 minute and your inconvenience is worth it in order to better protect the other 99%+ of people.
And no, you don't get prompted when loading local IP addresses, the content loads immediately and you just get the "connection is not secure" icon. That's because the connection is not secure.
So in short, this view held be some that the browser should blindly follow everything asked of it is non-sensical when viewed in the broader context of who it's made for. If you don't like it, go and use... well... they're all heading this direction so good luck with that!

• • •

Missing some Tweet in this thread? You can try to force a refresh
 

Keep Current with Troy Hunt

Troy Hunt Profile picture

Stay in touch and get notified when new unrolls are available from this author!

Read all threads

This Thread may be Removed Anytime!

PDF

Twitter may remove this content at anytime! Save it as PDF for later use!

Try unrolling a thread yourself!

how to unroll video
  1. Follow @ThreadReaderApp to mention us!

  2. From a Twitter thread mention us with a keyword "unroll"
@threadreaderapp unroll

Practice here first or read more on our help page!

More from @troyhunt

6 Aug
I like the principal behind this and I’ve got a lot more confidence in Apple to do it in a privacy-centric fashion than others: arstechnica.com/tech-policy/20…
But some of the comments in there seem to really miss the mark, for example “Client-side scanning on one ‘end’ of the communication breaks the security of the transmission”. Huh? It’s being done outside the context of any transmission, how does it “break the security”?!
Or this one: “informing a third party (the parent) about the content of the communication undermines its privacy”. This a cornerstone of parental controls, seeing what your kids are doing! The whole point is to limit their ability to sneak comms past parents.
Read 5 tweets
8 Jun
For folks asking about 8.4B record “RockYou2021” password list that’s in the news today, this is an aggregation of multiple other lists. For example, this password cracking list: crackstation.net/crackstation-w…
Among other things, it contains “every word in the Wikipedia databases” and words from the Project Gutenberg free ebook collection: gutenberg.org
Unlike the original 2009 RockYou data breach and consequent word list, these are not “pwned passwords”; it’s not a list of real world passwords compromised in data breaches, it’s just a list of words and the vast majority have *never* been passwords
Read 8 tweets
6 Jun
For my next IoT mission: I want to use Local Tuya to control lights without cloud. I don't want to solder stuff or pull lights out of the ceiling, you can no longer pull keys from the Tuya IoT portal (see descripting of vid) and I don't have a rooted Android. What's left?
All of this is just different levels of pain. BlueStacks and the Smart Life APK? My Tuya creds don't work. So screw it, just setup a dedicate Pi and use Tuya Convert to flash firmware. Nope, that won't work either: Image
I'm trying to find a "happy path" here, one that's not only happy for me, but one I can encourage others to follow. So far, that path remains having a cloud dependency and using the Tuya integration in @home_assistant. That's the least terrible of all the terrible options.
Read 10 tweets
27 May
I’m very happy to announce that @haveibeenpwned’s Pwned Passwords is now open source under the @dotnetfdn. Now we’ve got some work to do: building an ingestion pipeline for new passwords provided by the @FBI on an ongoing basis. This is super cool 😎 troyhunt.com/pwned-password…
There’s so much I love about this, starting with the fact that it removes a huge barrier for many orgs considering using Pwned Passwords: if I have an unfortunate jet ski related accident and can no longer run the service, you can pick it up and run it yourself.
And because all the passwords are already freely downloadable from @haveibeenpwned, all the data is already in the public domain. Open sourcing the code compliments the already open sourced data.
Read 7 tweets
25 May
It’s finally here - the @haveibeenpwned 3D logo 😎 The reason I bought the @Prusa3D in the first place was to make a bunch of these and hand them out in my travels. A little tweaking to do then I’ll pump out a bunch and give ‘em away. ImageImage
Pretty happy with this now, might need to start some mass production: Image
I think I know what I have to do now… 🙂 Image
Read 4 tweets
18 May
Is there a device to keep multi-monitor setups aligned? Other than duct tape, of course. Image
Alrighty, fixing this problem: first up, a bunch of 25mm Velcro measured and cut to size for a nice vertical fit along the edge of each screen (the 50mm one comes later) ImageImageImage
Next, some spirit level perfection to keep the centre screen straight and the same distance on each end off the wall, plus the Ergotron arm well and truly tightened up ImageImageImage
Read 5 tweets

Did Thread Reader help you today?

Support us! We are indie developers!


This site is made by just two indie developers on a laptop doing marketing, support and development! Read more about the story.

Become a Premium Member ($3/month or $30/year) and get exclusive features!

Become Premium

Too expensive? Make a small donation by buying us coffee ($5) or help with server cost ($10)

Donate via Paypal Become our Patreon

Thank you for your support!

Follow Us on Twitter!

:(