Hacker News new | past | comments | ask | show | jobs | submit login

Except there is no way to support HTTPs without ending up with people sharing https:// links that won't work for non-HTTPs users.

I really wish SSL/TLS would have used something like starttls. And yes, that means needing HSTS preload (or better yet a DNS-based alternative) to prevent downgrade attacks, but we do need that with https:// anyway.




Like non https users cannot remove the s manually?




Consider applying for YC's Fall 2025 batch! Applications are open till Aug 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: