Most security scanning software will ding any site that doesn't use HSTS
You're probably the target of a MITM attack. Or you've done something weird, like taking a job with an employer that MITMs your web traffic then refusing to install their MITM certificates.
[1] https://www.ssllabs.com/ssltest/analyze.html?d=daniel.haxx.s...
They were complaining that their battery life on their phone just got decimated recently and kept dying over and over. I believe I was helping to troubleshoot, so I had them turn on airplane mode, he flipped it and complaining of something else annoying happening and saying oh yeah my phone airplane mode doesn't work, I still get internet. I was totally baffled, it was all very weird to me.
A little bit of time later that person got busted as a part of a big local drug bust. I'm assuming that's how they tap phones.
It seems Firefox notices this and refuses to contact the site, and Chrome notices this and lets me override, but generally I don't see this failure mode. I wonder what is significant about this particular website.
I unsportingly separate work hardware from personal, no idea if my employer's likely MITM nonsense would have the same behaviour.
Learned something today, albeit with details missing. Oh and Vodafone employee if you're reading this? None of your tech works for shit.
Encrypted transit but you might be talking with the hacker on the other end == worthless.
And with plaintext transit you cannot prove integrity during transit AND also not prove talking with the proper endpoint.
In short: Browser really is warning you that something is fishy. Don’t shoot the messenger.
Firefox makes you fix the root problem.