Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Except the standards org that defines HTTP is the IETF, not the W3C...


Opps! You're right, the W3C only helped author it.

I was also wrong to say that w3.org never redirects to HTTPS. If the browsers sends a Upgrade-Insecure-Requests HTTP-header, then it redirects. That allows it to support all browsers as securely as possible.

Sites like whynohttps.com and observatory.mozilla.org should really test for this pattern.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: