Hacker News new | ask | show | jobs
by yawpitch 569 days ago
Just love this. My particular favorite is sending the http:// version of everything instead of https://.
2 comments

In my workplace people also set the machines to forget the redirects from time to time¹. So that it's not a given that the http:// will lead to anything.

1 - How? I have no idea. They are more expert than the author.

Don’t most browsers just auto direct to https though?
Only if there is HSTS (=if the site was visited previously and told the browser to always switch to https for the generally-6 months duration).
Yes, but the redirection takes both time and energy, that’s what makes it such a good form of sabotage, the grit in the engine that’s too small to notice but still leads to pain and cost.