Hacker News new | ask | show | jobs
by pfg 3217 days ago
Are you suggesting this change merely for users navigating to IP addresses in reserved IP space, or for everything?

If it's the latter, all that stands between an active MitM and my paypal.com credentials is a non-blocking "Not Secure" indicator in the address bar. That's not really acceptable.

1 comments

I just feel like separating the concerns of

1) Identity of the server

2) If the connection to the server is encrypted or not

would be a good idea in modern browsers. Because the article is completely correct, everything as it is right now essentially disincentives anyone producing IoT or any other kinds of consumer based lan devices from using https.