TLS everywhere has a major flaw and needs refining to the page level.
Kevin Chadwick <[email protected]> Thu, 15 Feb 2018 12:34:49 +0000
| Newsgroups | gmane.comp.mozilla.security |
|---|---|
| Message-ID | <[email protected]> |
The cookies etc. should be SSL only. Particular pages enforced, sure. Enforcing TLS with HSTS sitewide means that users with failed bios/laptop batteries have to know to reset their clock or get used to bypassing SSL warnings or use out of date browsers to access sites. A fairly common problem, not good. Think real world, please. This hurts the most vulnerable. Another solution may be to remove the cert is not valid YET restriction but that is a can of worms. Thankyou