logoalt Hacker News

baobunyesterday at 11:35 AM1 replyview on HN

> Modern versions of Chrom{e|ium} & Firefox (and other browsers based on them) have defaulted to HTTPS when the protocol is not specified.

This is not true but it would be nice if it was.

https://news.ycombinator.com/item?id=46443199


Replies

dspillettyesterday at 12:10 PM

Hmm. I am perhaps confusing announced plans, and the effect of the HSTS preload lists, with actually released changes to defaults.

I'll have to install some fresh VMs and see what behaviour I get out-of-the-box with no HSTS cache (and sites not on the preload lists) on various OSs, to correct my understanding.