I love TLS. I think it's the least worst system we have. But HTTPS only outside of it's proper context does a lot of harm and it's pointless. HTTP and HTTPS are two great tastes that go great together.
I love TLS. I think it's the least worst system we have. But HTTPS only outside of it's proper context does a lot of harm and it's pointless. HTTP and HTTPS are two great tastes that go great together.
Secondly, it makes passive surveillance and data gathering much harder. You can still track which sites a user connects to, but you can't see which pages they access or the contents of those pages. You can still actively intercept those connections via MitM but that requires users to manually install an MitM certificate on their system so they should be aware when it's occurring.
Thirdly, it makes it harder to intentionally block or break HTTPS altogether at the network level to force users to fall back to unencrypted HTTP. (TLS downgrade attacks are different from and much more difficult than, for example, just blocking all traffic on port 443.) If there's no unencrypted fallback, then users will complain loudly when they can't access sites.
If your main concern is old computers the solution is to use a proxy that strips the encryption.
[1] https://www.bankinfosecurity.com/github-hit-by-its-largest-d...
Why not also use the proxy to add encryption when it is missing. Then "HTTPS-only" is not necessary. The decision of which scheme to use, http:// or https://, rests with the user, not the server.
It is being added by the proxy server listening on the loopback which connects to the remote website.
Browser connects to forward proxy on port 80, forward proxy (compiled with SSL library) connects to target IP on port 443.
This is how one can, e.g, use clients that are not SSL-enabled to access websites, etc. that require SSL.
For example, if forward proxy is listening on 127.0.0.1:80, we can make an encrypted connection to example.com using original *hobbit netcat which does not support SSL.
echo -e 'GET / HTTP/1.1\r\nHost: example.com\r\nConnection: close\r\n\r\n" |nc -vvn 127.0.0.1 80
It is probably more popular to use stunnel for this purpose instead of a forward proxy.To be honest there are still some sites that do not, and will probably never, offer HTTPS and I have to account for those with the proxy setup. For these websites I might assign them a different local IP that does not add encryption.
In running this setup there are some times where I find that for one reason or another "HTTPS-only" on the server side has failed to catch every instance where http:// should be https://. I use many different clients, the least of which is the modern browser which may have some whizbang features to try to enforce "HTTPS-everywhere". The clients I use more are simpler, less complex and do not have such features. Instead of relying on the modern browser, I rely on an extensive proxy configuration to make sure everything gets encrypted (when appropriate).