Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Author here! Surprising thing when researching this was how fast some of the stuff talked about a year ago is already upon us in the upcoming browser releases:

- If you're running Chrome Canary, try visiting http://html5demos.com/geo (which hasn't yet been updated for HTTPS yet). Geolocation fails, consistently over HTTP

- Firefox nightlies has already started warning for sites that allow POST over HTTP: https://www.fxsitecompat.com/en-CA/docs/2015/non-https-sites... (for type=password only, see dsp1234's note below)

PS. since this article has gotten so much attention: does anyone on HN know of a newer app than Driftnet or Etherpeg for reassembling images from HTTP traffic? I wanted something newer (that people could install themselves on a Mac) but couldn't find anything.



Here is the Chrome bug report to remove geolocation support for insecure origins (in Chrome 50):

https://codereview.chromium.org/1530403002/

And here is the Firefox feature request, filed in 2014:

https://bugzilla.mozilla.org/show_bug.cgi?id=1072859


The geolocation demo works on Chrome for Android though.


Firefox nightlies has already started warning for sites that allow POST over HTTP

only for pages that contain a password input




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: