top | item 37615862

(no title)

cotillion | 2 years ago

Ouch.

Apparently Firefox has "Https First" also but requires the pref dom.security.https_first to be set.

"HTTPS-Only Mode" is obviously best if you can do that.

discuss

order

rany_|2 years ago

You'd still need to resist the urge to not press "allow me anyway" and to be honest, even I'd click it knowing the risk (I just want to visit the damn site!). This doesn't solve anything unless the prompt is extremely suspicious (like the prompt showing for Google.com or some other site I know supports HTTPS).

rany_|2 years ago

Replying to myself but also, they could easily trick you into clicking some link and exploiting you that way. HTTP isn't the issue here, it's just being exploited so they don't have to get you to click some link.

In all likelihood they'd do that if the less direct/obvious method of transmission didn't work.