Re: Auto-selection of secure protocol
"Eddie Turfboer" <[email protected]>
| Newsgroups | gmane.comp.mozilla.wishlist |
|---|---|
| Message-ID | <[email protected]> |
In my opinion it is the responsibility of the provider of the service to weigh in the need for an secure connection. Obviously for an bank website one needs a secured connection. I mean you define an fine problem, though I do not agree with your proposed solution. Maybe it is more suited to show the user that there is also a secured connection available (when that is automatically sensed) and if the user chooses to load the page using a secured connection do so from that point forward. Greetings, Eddie. On Fri, Oct 10, 2008 at 9:31 AM, Guillaume Michaud <[email protected]>wrote: > Hi ! > > With the increasing number of online services (Gmail, Meebo and so on), > privacy and security on the web is of an increasing importance, which > reflects on Mozilla's attitude towards SSL certificates and so on. > Some of such online services (such as Gmail and Meebo, again) can be > accessed securely with an encrypted connection. However, this is not always > the case, and when it is possible, the service providers seldomly "force" > their users to use encryption. > In short, this means that users who are not computer-savvy never use the > encrypted versions. > > This is mainly because when a user types "myurl" in the url bar of his > browser, he is automatically redirected to http://myurl by the browser, > and > never to https://myurl, excepts if the service provider has enabled the > redirection. > > It could be interesting to offer the user a functionnality which, by > default, allows the user to use the encrypted version of a web page, that > is > to say to redirect him to https://myurl instead of http://myurl when he > types "myurl" in the adresse bar. > The problem of https://myurl and http://myurl not being the same page > could > be addressed with a white-list system, or exceptions. > > The objective is clearly to enable non computer-savvy to use encrypted > versions by default, wether they know there is an encrypted version or not. > > What do you think about it ? > > Guillaume > _______________________________________________ > wishlist mailing list > [email protected] > https://lists.mozilla.org/listinfo/wishlist >