May 7, 2015 By Douglas Bonderud 2 min read

As noted by Mark Nottingham, chair of the IETF HTTP Working Group, industry practice when it comes to the HTTP/HTTPS debate has been to err on the side of carrot rather than stick — give users and developers a reason to opt in and convert to HTTPS rather than trying to compel their obedience. Now, the Mozilla Foundation has announced a different tactic: In the near future, all new features in its Firefox browser will only be available to secure websites. But will this new HTTPS requirement really work better than the “carrots” to produce a more secure Web, or is this stick just too sharp?

Get Secure or Get Out

According to InfoWorld, while there’s no firm date for the Firefox switch-over, the consequence of not going HTTPS was made clear by Mozilla: Without a secure connection, specific features — especially those related to users’ security and privacy — will be instantly disabled in the browser, while new developments will be off-limits until developers and websites can show they’re HTTPS-compliant. But why toss out the carrot of faster protocols and better encryption to lure HTTPS converts and instead opt for an ultimatum?

Part of the reason is Let’s Encrypt, a certificate authority co-sponsored by Mozilla. The idea behind Let’s Encrypt is to provide free TLS certificates to any domain name owner, effectively removing the problems of cost and ongoing management. In effect, the Mozilla Foundation sees HTTPS as the future of Web security, and it believes it has the tools to make HTTPS less of a chore and more of a certainty.

Not surprisingly, there’s some pushback. Cryptography software developer Sven Slootweg, for example, wrote on his blog that Let’s Encrypt may not account for things like the developer use of wild-card domains, effectively locking them out of features even though they’ve done nothing wrong. He also argues that the HTTPS requirement goes against the idea of an open Web. However, Mozilla stated that it is looking for user feedback before setting a firm date for the switch, giving users ample time to make the necessary changes and comply with Firefox.

“Transitioning the Web to HTTPS is going to take some time, so whatever a website does today, it will still work for months or years,” Firefox Security Lead Richard Barnes told Tom’s Hardware.

Strange Security?

Not all companies agree that HTTPS is the way of the future. Facebook, for example, is willing to provide free Internet access for users in countries such as India, Tanzania, Kenya and Colombia through its Internet.org initiative, but only for sites that don’t use HTTPS, The Register reported. The social media giant says that this “walled garden” program is necessary because its servers can’t support HTTPS and will either have all encryption stripped or simply be rejected. Micheal Horowitz of Computerworld, meanwhile, argued that HTTPS is in large measure smoke and mirrors. While browsers could do things like periodically validate their list of trusted root CAs, right now there’s more value in the “S” than what’s underneath.

Mozilla and other search giants don’t see it this way. While HTTPS isn’t perfect, the idea is to use it as a launching pad for other security developments and make the Web a safer place along the way. The problem? The HTTPS requirement might also make the Web less open-ended and more invite-only.

More from

Autonomous security for cloud in AWS: Harnessing the power of AI for a secure future

3 min read - As the digital world evolves, businesses increasingly rely on cloud solutions to store data, run operations and manage applications. However, with this growth comes the challenge of ensuring that cloud environments remain secure and compliant with ever-changing regulations. This is where the idea of autonomous security for cloud (ASC) comes into play.Security and compliance aren't just technical buzzwords; they are crucial for businesses of all sizes. With data breaches and cyber threats on the rise, having systems that ensure your…

Adversarial advantage: Using nation-state threat analysis to strengthen U.S. cybersecurity

4 min read - Nation-state adversaries are changing their approach, pivoting from data destruction to prioritizing stealth and espionage. According to the Microsoft 2023 Digital Defense Report, "nation-state attackers are increasing their investments and launching more sophisticated cyberattacks to evade detection and achieve strategic priorities."These actors pose a critical threat to United States infrastructure and protected data, and compromising either resource could put citizens at risk.Thankfully, there's an upside to these malicious efforts: information. By analyzing nation-state tactics, government agencies and private enterprises are…

6 Principles of Operational Technology Cybersecurity released by joint NSA initiative

4 min read - Today’s critical infrastructure organizations rely on operational technology (OT) to help control and manage the systems and processes required to keep critical services to the public running. However, due to the highly integrated nature of OT deployments, cybersecurity has become a primary concern.On October 2, 2024, the NSA (National Security Agency) released a new CSI titled “Principles of Operational Technology Cybersecurity.” This new guide was created in collaboration with the Australian Signals Directorate’s Australian Cyber Security Centre (ASD SCSC) to…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today