Disable HTTPS upgrade?
Disable HTTPS upgrade?
Posted Mar 6, 2025 17:37 UTC (Thu) by draco (subscriber, #1792)In reply to: Disable HTTPS upgrade? by arita
Parent article: Firefox 136.0 released
Browsers have long resisted adding any DNS lookups to the dependency chain for loading a page because they say people are extremely latency sensitive. It sounds like platform support for arbitrary DNS record types has been problematic too.
Hence they've ignored a number of records that have been proposed to improve security (e.g., TLSA).
I think that RFC was developed with their input to try to address their needs, so it's really sad to see it not be enabled. Though it's at least implemented, which is progress, I guess?
