As noted by Mark Nottingham, chair of the IETF HTTP Working Group, industry practice when it comes to the HTTP/HTTPS debate has been to err on the side of carrot rather than stick — give users and developers a reason to opt in and convert to HTTPS rather than trying to compel their obedience. Now, the Mozilla Foundation has announced a different tactic: In the near future, all new features in its Firefox browser will only be available to secure websites. But will this new HTTPS requirement really work better than the “carrots” to produce a more secure Web, or is this stick just too sharp?

Get Secure or Get Out

According to InfoWorld, while there’s no firm date for the Firefox switch-over, the consequence of not going HTTPS was made clear by Mozilla: Without a secure connection, specific features — especially those related to users’ security and privacy — will be instantly disabled in the browser, while new developments will be off-limits until developers and websites can show they’re HTTPS-compliant. But why toss out the carrot of faster protocols and better encryption to lure HTTPS converts and instead opt for an ultimatum?

Part of the reason is Let’s Encrypt, a certificate authority co-sponsored by Mozilla. The idea behind Let’s Encrypt is to provide free TLS certificates to any domain name owner, effectively removing the problems of cost and ongoing management. In effect, the Mozilla Foundation sees HTTPS as the future of Web security, and it believes it has the tools to make HTTPS less of a chore and more of a certainty.

Not surprisingly, there’s some pushback. Cryptography software developer Sven Slootweg, for example, wrote on his blog that Let’s Encrypt may not account for things like the developer use of wild-card domains, effectively locking them out of features even though they’ve done nothing wrong. He also argues that the HTTPS requirement goes against the idea of an open Web. However, Mozilla stated that it is looking for user feedback before setting a firm date for the switch, giving users ample time to make the necessary changes and comply with Firefox.

“Transitioning the Web to HTTPS is going to take some time, so whatever a website does today, it will still work for months or years,” Firefox Security Lead Richard Barnes told Tom’s Hardware.

Strange Security?

Not all companies agree that HTTPS is the way of the future. Facebook, for example, is willing to provide free Internet access for users in countries such as India, Tanzania, Kenya and Colombia through its Internet.org initiative, but only for sites that don’t use HTTPS, The Register reported. The social media giant says that this “walled garden” program is necessary because its servers can’t support HTTPS and will either have all encryption stripped or simply be rejected. Micheal Horowitz of Computerworld, meanwhile, argued that HTTPS is in large measure smoke and mirrors. While browsers could do things like periodically validate their list of trusted root CAs, right now there’s more value in the “S” than what’s underneath.

Mozilla and other search giants don’t see it this way. While HTTPS isn’t perfect, the idea is to use it as a launching pad for other security developments and make the Web a safer place along the way. The problem? The HTTPS requirement might also make the Web less open-ended and more invite-only.

More from

Are you ready to build your organization’s digital trust?

4 min read - As organizations continue their digital transformation journey, they need to be able to trust that their digital assets are secure. That’s not easy in today’s environment, as the numbers and sophistication of cyberattacks increase and organizations face challenges from remote work and insider behavior. Digital trust can make your organization’s digital transformation stronger. A lack of digital trust can do irreparable harm. However, according to ISACA’s State of Digital Trust 2023 report, too many organizations struggle to define and implement…

Most organizations want security vendor consolidation

4 min read - Cybersecurity is complicated, to say the least. Maintaining a strong security posture goes far beyond knowing about attack groups and their devious TTPs. Merely understanding, coordinating and unifying security tools can be challenging. We quickly passed through the “not if, but when” stage of cyberattacks. Now, it’s commonplace for companies to have experienced multiple breaches. Today, cybersecurity has taken a seat in core business strategy discussions as the risks and costs have risen dramatically. For this reason, 75% of organizations…

How IBM secures the U.S. Open

2 min read - More than 15 million tennis fans around the world visited the US Open app and website this year, checking scores, poring over statistics and watching highlights from hundreds of matches over the two weeks of the tournament. To help develop this world-class digital experience, IBM Consulting worked closely with the USTA, developing powerful generative AI models that transform tennis data into insights and original content. Using IBM watsonx, a next-generation AI and data platform, the team built and managed the entire…

How the FBI Fights Back Against Worldwide Cyberattacks

5 min read - In the worldwide battle against malicious cyberattacks, there is no organization more central to the fight than the Federal Bureau of Investigation (FBI). And recent years have proven that the bureau still has some surprises up its sleeve. In early May, the U.S. Department of Justice announced the conclusion of a U.S. government operation called MEDUSA. The operation disrupted a global peer-to-peer network of computers compromised by malware called Snake. Attributed to a unit of the Russian government Security Service,…