Re: HTTPS at W3C.

On Mon, 17 Nov 2014, Mike West wrote:

> On Mon, Nov 17, 2014 at 7:13 PM, Ted Guild <> wrote:

> It seems here that you're letting perfect be the enemy of good. For
> example, I'd be a little bit happier if I could choose to point people to
> without being redirected to HTTP.
> That's more or less what `` seems to be doing, and it's
> certainly better than nothing.
> * Mixed content warning algorithms are based on the page as it is
>> retrieved and not as it is served.
> I'm sure you're aware of this, but that is intentional behavior.
>> So even with HSTS and us redirecting
>> all HTTP to the corresponding HTTPS our users will get inundated with
>> mixed content warnings.
> Until you fix the underlying resources. :)

We have tons of historic content that can't be upgraded. There is a plan 
to rewrite all the mailing list archives as it can be relatively easy to 

So if the behaviour in
is intentional to force people to upgrade references, it is still 
problematic to display a warning that is untrue.

Even worse than that, if refers to, then 
is redirected to, then the icon basically 
says that everything was securely transferred, which was NOT the case. Is 
that an intentional behaviour? :)

Baroula que barouleras, au tiƩu toujou t'entourneras.


Received on Wednesday, 19 November 2014 12:20:58 UTC