disabling HSTS
disabling HSTS
Posted Apr 19, 2017 1:28 UTC (Wed) by tialaramex (subscriber, #21167)In reply to: disabling HSTS by linuxrocks123
Parent article: Tor exit node operator arrested in Russia (TorServers.net blog)
An about:config option would presumably be global, so the effect is "set this, and then you can ignore stuff by clicking through it" which is exactly what we already know doesn't work. But the facts have never impinged on projects like Pale Moon before and I don't see that changing.
[ Fun fact: Pale Moon decided Let's Encrypt is untrustworthy because the lead developer of Pale Moon thinks a CA should be responsible for preventing phishing and malvertising. Also, some hard to follow logic whereby there's an "inherent lack of validation" in Let's Encrypt's validation system (I have a long rant about this, but basically Ballot 169 rules significantly tighten up validation for the Web PKI, three of the nine methods specified in Ballot 169 are modelled on how Let's Encrypt already worked when the ballot was written, those three Ballot 169 methods are basically like the ELI5 sketch of how Let's Encrypt does validation, they don't really capture the nuances, but at least they're an improvement on the total ignorance that reigned prior). You won't have noticed because "untrustworthy" for Pale Moon turns out to mean nothing whatsoever, Let's Encrypt certificates still work fine, not that it matters because presumably you'd just click through the errors anyway and press on. ]
