HTTP or HTTPS?
I'm building a new static website, minimalist design etc, mostly about my hobbies and interests. Although, who knows, maybe in the future I will cover more controversial topics ...
Is there any good reason *not* to use HTTPS?
HTTP or HTTPS?
I'm building a new static website, minimalist design etc, mostly about my hobbies and interests. Although, who knows, maybe in the future I will cover more controversial topics ...
Is there any good reason *not* to use HTTPS?
Maybe noteworthy to some:
If you see "https-rulesets.org" in your #DNS logs going forward, there's a #browser somewhere on your network that needs attention.
The #HTTPSEverywhere browser extension, which was retired a couple years ago by EFF, periodically checked "https-rulesets.org" for updates. That domain expired this week and got snatched up by a squatter. I don't think it resolved at all for most of 2024 and nothing should be querying it now.
This push for #HTTPSEverywhere would've been perfectly fine if it just focused on #HTTPS / #TLS / #SSL as an option always available. But no, it also pushed for it to be mandatory (even if it doesn't make sense if you look at the #threatmodel), and as a result pretty much everything in the #web cannot be accessed with a #browser that doesn't have an up-to-date enough TLS support. Which is fine I guess if you're on a modern computer anyway, but a pain if you're on #retrocomputing. :seija_coffee:
The #LetsEncrypt #centralization is also a serious concern, which is why I avoided using it for my #VPS.
RE: https://hamishcampbell.com/a-balanced-and-pragmatic-approach-to-native-openweb-security/
Recommened Firefox/Chrome Add-ons
I wonder how many companies have gone out of business simply because they didn't use https for their websites.
DYN that by default #Azure #functions do not enforce #HTTPS only? Rather you must configure HTTP to redirect to HTTPS.
Also, interestingly enough I found this factoid in an Azure Docs section on VNet integration.
@questionable_ole #uBlockOrigin is a must, and I'll also shill for #NoScript, #HTTPSEverywhere, and #Bitwarden. #FacebookContainer is also good if you use #Meta services.
La morte di Peter Eckersley, il fondatore di Let's Encrypt, ha sconvolto gli informatici di tutto il mondo
https://poliverso.org/display/0477a01e-1563-135b-73bf-c39316965916
Расширение HTTPS-Everywhere больше не нужно, да-да. Режим встроен в браузер, конечно.
Тем временем рабочий gmail: зависает на минуту в этом режиме. На двух разных ОС, независимо от настроек DNS и флагов about:config
Есть ещё скрин, где минута уходит на некий "TLS Setup".
Выключил опцию. Посмотрим.
@eff the whole point to the #HTTPSEverywhere db is to skip the lag of attempting a fetch that will potentially fail. This new version will require people to fetch the javascript file, execute it, then do another network fetch to check the site. How is that better than a browser that just tries HTTPS outright and reverts to http when it fails?
#DecentralEyes pretends to improve the privacy by replacing some common JS libraries served through CDNs with locally stored copies. Not really sure how important the effect is (e.g. what fraction of all CDN requests is blocked this way), but it never broke any site for me, hence why not?
#HTTPSEverywhere ensures that all sites supporting SSL connection do actually use it. A few years ago I took care to write the rules for my favorite sites myself. Now everything works mostly out of box.
Auf dem Handy habe ich browserunabhängig #Blokada, #Warden, #UntrackMe und #AFWall.
In Fennec #ublockorigin, #httpseverywhere, #decentraleyes und #bitwarden.
Die Geräte von Frau und K1 sind genauso eingerichtet.
Eine Zeitlang hatte ich noch #Shelter am laufen aber das hat irgendwann Probleme verursacht... Ich weiß nur leider nicht mehr, welche. :-/
@tinyrabbit @downey ATM I see that #HTTPSEverywhere hogs ~102mb RAM, WTF. /cc @eff
FEDI SECURITY ISSUE (please boost)
When we attempted to access a page at fediverse.party recently, we were served a page with an insecure connection, this is despite using #TorBrowser, which supposedly has #HttpsEverywhere?
So does anyone know what is going on here? Is fediverse.party susceptible to a #downgradeAttack?
Please boost so we can get to the bottom of it.
Thanks to all the developers working on #FreeSoftware #Security at #ClamAv, #GnuPG, #PrivacyBadger, #HTTPSEverywhere, #UBlockOrigin and many other groups who enable users to #StayConnected in a safe way - #ilovefs
@eff
@kantel +lol+ Das ist ja lustig.
Ich verdächtige jetzt einfach mal #HTTPSEverywhere von der @eff.
Oi, wir haben 2020. Die 90er Jahre wollen ihr unverschlüsseltes #HTTP zurück.
Es kommt vor, dass ich durch Browser Fremder das Internet betrachte und dabei regelrecht erschrecke. Daran merke ich, wie sehr ich daran gewöhnt bin, das Netz gefiltert durch die von mir installierten Browser-Erweiterungen zu betrachten. Viele Menschen wissen überhaupt nicht, wie leicht es ist, schöner zu browsen. ...
#Adblocker #Bitwarden #Browser #Cookies #Decentraleyes #Erweiterung #HTTPSEverywhere #Mailvelope #Passwordsafe #PrivacyBadger #Tracker #uBlockOrigin
https://svenbrier.de/7-browser-erweiterungen-fuer-dein-online-upgrade/
Instead of showing "Not secure" in the location bar, why not just not render the page if it's on plaintext HTTP and tell the user
"This connection is unencrypted."