• Login
    • Search
    • Categories
    • Recent
    • Tags
    • Users
    • Groups
    • Rules
    • Help

    Do more on the web, with a fast and secure browser!

    Download Opera browser with:

    • built-in ad blocker
    • battery saver
    • free VPN
    Download Opera

    HTTPS Always

    Feedback for the Forums
    3
    10
    3015
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • A Former User
      A Former User last edited by

      Hi,

      I would suggest making secure connection (HTTPS) available also when not signed in. As it currently is feels a bit obsolete in these times of surveillance and all kinds of spying and tracking of usersโ€™ activities.

      Also, after signing in at https://auth.opera.com/account/login?service=forums&return_url=http://forums.opera.com/, as can be seen, the return-URL is http://forums.opera.com/, which means the http://forums.opera.com/ is opened and then redirected to https://forums.opera.com/. That does not look like a very secure solution.

      If signing in without specifying a service (i.e. at https://auth.opera.com/account/login), https://auth.opera.com/account/login/success?service=auth is opened, and there the forum-link is http://forums.opera.com/.

      Best would be to implement HSTS (https://en.wikipedia.org/wiki/HTTP_Strict_Transport_Security , see also https://www.eff.org/deeplinks/2014/02/websites-hsts). Second best would be to at least make HTTPS available and usable also when not signed in (and changing the return-URL and forum-link mentioned above). Then people could add forums.opera.com at opera://net-internals/#hsts or enable the the ruleset for Opera in HTTPS Everywhere (https://www.eff.org/https-everywhere). Now it is impossible to sign in with that ruleset enabled.

      Thanks. ๐Ÿ‘ฝ

      Reply Quote 0
        1 Reply Last reply
      • A Former User
        A Former User last edited by

        No.

        1. This is a technical support forum.
        2. I like it the way it is.
        Reply Quote 0
          1 Reply Last reply
        • A Former User
          A Former User last edited by
          1. How is that relevant?
          2. What is to like in it?

          Thanks.

          Reply Quote 0
            1 Reply Last reply
          • A Former User
            A Former User last edited by

            Directly.
            If a hoover has an Opera installed, the forums should be readable - easily - from a hoover.
            Hoovers don't do hetepepese.

            Reply Quote 0
              1 Reply Last reply
            • A Former User
              A Former User last edited by
              1. Making the secure connection available when not signed in does not make the insecure connection unavailable.
              2. Clients that donโ€™t support HTTPS also donโ€™t support HSTS, so using that would not cause problems for those clients.
              3. Tell those hoovers to get ready for HTTP/2 (https://http2.github.io/).
              Reply Quote 0
                1 Reply Last reply
              • A Former User
                A Former User last edited by

                :rolleyes: <_<

                Reply Quote 0
                  1 Reply Last reply
                • A Former User
                  A Former User last edited by

                  What's your problem?
                  Really?
                  Myself personally ain't got no prom with all that stuff your seem to be talking about.
                  I blop a letter, the autofill autofills it to forums.opera.com, the [Overview] page loads, autoreloads to the signed-in state, https, I'm on "Overview", signed in, no prom, blah-blah, now you come, tell me as if "we all gonna die" - or what?
                  What's the problem, dudes? ๐Ÿ™‚

                  Reply Quote 0
                    1 Reply Last reply
                  • digmed
                    digmed last edited by

                    Making HTTPS available also when not signed in is a perfectly valid request. Unfortunately I can't promise this will be prioritized, but we will be looking into making all Opera sites HTTPS by default.

                    Reply Quote 0
                      1 Reply Last reply
                    • A Former User
                      A Former User last edited by

                      Thanks digmed. ๐Ÿ†™

                      Making all Opera-sites HTTPS by default is an ambitious plan, and it will take some time, I guess.

                      Why not, as a small first step, remove the redirect to HTTP for forums.opera.com. ๐Ÿ˜‰

                      Reply Quote 0
                        1 Reply Last reply
                      • A Former User
                        A Former User last edited by

                        ๐Ÿ˜•
                        :faint:

                        Reply Quote 0
                          1 Reply Last reply
                        • First post
                          Last post

                        Computer browsers

                        • Opera for Windows
                        • Opera for Mac
                        • Opera for Linux
                        • Opera beta version
                        • Opera USB

                        Mobile browsers

                        • Opera for Android
                        • Opera Mini
                        • Opera Touch
                        • Opera for basic phones

                        • Add-ons
                        • Opera account
                        • Wallpapers
                        • Opera Ads

                        • Help & support
                        • Opera blogs
                        • Opera forums
                        • Dev.Opera

                        • Security
                        • Privacy
                        • Cookies Policy
                        • EULA
                        • Terms of Service

                        • About Opera
                        • Press info
                        • Jobs
                        • Investors
                        • Become a partner
                        • Contact us

                        Follow Opera

                        • Opera - Facebook
                        • Opera - Twitter
                        • Opera - YouTube
                        • Opera - LinkedIn
                        • Opera - Instagram

                        ยฉ Opera Software 1995-2025