But after a bit of reflection I now think that in this specific case there's nothing bad about using http. Services are offered on a first come first serve basis to a large but closed group of valid users. Key is that there are a bunch of real world processes that follow the initial trigger with no practical way for any other party to benefit.
The site is extremely simple but blazingly fast.
What is the benefit to turning https off?
I'm really tired of using a computer and feeling like a passenger rather than the driver.
https://superuser.com/questions/1721511/firefox-allow-http-u...
https://support.mozilla.org/en-US/kb/https-only-prefs#w_enab...
There’s plenty of reasons to be mad at big corporations. But for now at least, Firefox still supports your right to make bad life choices on the internet.
Some components of Public Key Infrastructure itself use unencrypted HTTP for this very reason. See Online Certificate Status Protocol (OCSP) - a method for distributing Certificate Revocation Lists.
Many Linux distributions operate package repositories in this manner. It allows caching of packages through a variety of methods.
Generally, CDNs can distribute signed HTTP content without requiring a customer to share a private key as would normally be required by HTTPS. So long as confidentiality is not a requirement.
The IETF, Google, and Cloudflare have been developing standards for it.
https://www.ietf.org/archive/id/draft-ietf-httpbis-message-s...
https://wicg.github.io/webpackage/draft-yasskin-http-origin-...
Parent post didn't expliticly ask for browser context only.
Mitm attacks seem incredibly dangerous in a package repo. Signing only gets you so far - and they probably don’t protect you from downgrade attacks.
There's no benefit to saving a file on a floppy disk, but if I tell my computer to copy a file to my floppy drive, I don't expect it to say "No, can't do that. You should be using a USB flash drive--they're better in all ways!"
But I'm asking you: Why do you want to use unencrypted HTTP? Surely there must be some reason you want to do that, right? You (and others) clearly care a lot about this. I'm sure you're not an idiot. Help me understand your point of view here?
At the end of the day, I worked around all of this browser helpfulness by using Firefox and re-enabling TLS 1.1 in Firefox's settings. I never actually managed to force any browser to use http:// despite trying many proposed solutions in this thread and on the web.
But all that aside, it doesn't really matter why I want to use unencrypted HTTP. I am commanding my computer to do it, and I expect it to carry out my command. My computer is a tool. It should do what I want it to do, even if that might hurt me. If I type in sudo rm -rf /usr, I expect it to do what I tell it to do. Not ask "Why do you want to do that?"