This site will have limited functionality while we undergo maintenance to improve your experience. If an article doesn't solve your issue and you want to ask a question, we have our support community waiting to help you at @FirefoxSupport on Twitter and/r/firefox on Reddit.

Search Support

Avoid support scams. We will never ask you to call or text a phone number or share personal information. Please report suspicious activity using the “Report Abuse” option.

Learn More

Securely connect to websites via https first by default, if not then, use http as fallback. This will prevent downgrade attacks.

  • 2 replies
  • 1 has this problem
  • 7 views
  • Last reply by cor-el

more options

I have a suggestion. I would like for browsers to connect securely via https first by default to websites. When the browser checks that https is not supported by the website, it should downgrade to http, so do invalid certificates. This will prevent downgrade attacks and make HSTS headers optional. Browsers for years have been connecting to http by default, which I feel is a security risk. A kind of design flaw. Is an option to connect to https first by default a good idea?

I have a suggestion. I would like for browsers to connect securely via https first by default to websites. When the browser checks that https is not supported by the website, it should downgrade to http, so do invalid certificates. This will prevent downgrade attacks and make HSTS headers optional. Browsers for years have been connecting to http by default, which I feel is a security risk. A kind of design flaw. Is an option to connect to https first by default a good idea?

All Replies (2)

more options

You may submit suggestions to the developers here: https://input.mozilla.org/en-US/feedback

more options

See: