Conversation
Edited 21 days ago

I liked the green padlock in browsers that they removed. It was so comforting to see it suddenly appear after hours of debugging of the HTTPS port.

2
2
1

@Sominemo nono you had it right the first time

0
0
0

@Sominemo i remember complaining about some uk ad going "look for the green icon to know a site is safe" ( https://www.which.co.uk/news/article/does-the-green-padlock-mean-a-website-is-safe-aFkqh9a9F8Rv ) (and being downvoted on reddit about it) and like

yeah i see why it's removed, That's Not What It Means. even with EV certs that's not what it means.

1
0
1
@5225225 @Sominemo
the inverse is true however. red padlock/struck through shield/whatever: site is insecure
1
0
2

@charlotte @Sominemo oh yeah, you definitely shouldn't type any sensitive information into a plaintext site

the negative instead of positive feedback closer matches reality when Every* site has tls, and even before tbh

oh hey, chrome is https only (fullpage warning) by default(public, not lan sites) in october, that's neat (https://blog.google/security/https-by-defau/)

2
0
1

@5225225 @charlotte I had Firefox in https first mode for years now

1
0
1
@5225225 @Sominemo
imo they should also block javascript and addon objects on public http
1
0
2

@charlotte @Sominemo true, the 10 people that are intentionally boomer about this and go "https is bloat" also consider js to be bloat too

0
0
1

@Sominemo @charlotte yeah, that's honestly my biggest raccomendation in terms of "browser setting that are unobtrusive but have a significant impact"(assuming you treat the warnings as real)

though on the flip side every site should be on the hsts list too

0
0
1