Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I'm for this. Any computer capable of running FF83 is powerful enough to use HTTPS everywhere.

What it doesn't do, is force good TLS - there's nothing to stop a site using a weak algorithm, SSLv2/3, or old TLS versions.

It also wrecks network-level caching using appliances like Squid.



> What it doesn't do, is force good TLS - there's nothing to stop a site using a weak algorithm, SSLv2/3, or old TLS versions.

TLS 1.0 and 1.1 were disabled in Firefox 78 in June.


That's good news. I know there was some flip-flopping over this because of covid and gov sites requiring old encryption. Great to hear that it's now done with.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: