<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[HTTPS Always]]></title><description><![CDATA[<p dir="auto">Hi,</p>
<p dir="auto">I would suggest making secure connection (HTTPS) available also when not signed in. As it currently is feels a bit obsolete in these times of surveillance and all kinds of spying and tracking of users’ activities.</p>
<p dir="auto">Also, after signing in at <a href="https://auth.opera.com/account/login?service=forums&amp;return_url=http://forums.opera.com/" target="_blank" rel="noopener noreferrer nofollow ugc">https://auth.opera.com/account/login?service=forums&amp;return_url=http://forums.opera.com/</a>, as can be seen, the return-URL is <a href="http://forums.opera.com/" target="_blank" rel="noopener noreferrer nofollow ugc">http://forums.opera.com/</a>, which means the <a href="http://forums.opera.com/" target="_blank" rel="noopener noreferrer nofollow ugc">http://forums.opera.com/</a> is opened and then redirected to <a href="https://forums.opera.com/">https://forums.opera.com/</a>. That does not look like a very secure solution.</p>
<p dir="auto">If signing in without specifying a service (i.e. at <a href="https://auth.opera.com/account/login" target="_blank" rel="noopener noreferrer nofollow ugc">https://auth.opera.com/account/login</a>), <a href="https://auth.opera.com/account/login/success?service=auth" target="_blank" rel="noopener noreferrer nofollow ugc">https://auth.opera.com/account/login/success?service=auth</a> is opened, and there the forum-link is <a href="http://forums.opera.com/" target="_blank" rel="noopener noreferrer nofollow ugc">http://forums.opera.com/</a>.</p>
<p dir="auto">Best would be to implement HSTS (<a href="https://en.wikipedia.org/wiki/HTTP_Strict_Transport_Security" target="_blank" rel="noopener noreferrer nofollow ugc">https://en.wikipedia.org/wiki/HTTP_Strict_Transport_Security</a> , see also <a href="https://www.eff.org/deeplinks/2014/02/websites-hsts" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.eff.org/deeplinks/2014/02/websites-hsts</a>). Second best would be to at least make HTTPS available and usable also when not signed in (and changing the return-URL and forum-link mentioned above). Then people could add <a href="http://forums.opera.com" target="_blank" rel="noopener noreferrer nofollow ugc">forums.opera.com</a> at opera://net-internals/#hsts or enable the the ruleset for Opera in HTTPS Everywhere (<a href="https://www.eff.org/https-everywhere" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.eff.org/https-everywhere</a>). Now it is impossible to sign in with that ruleset enabled.</p>
<p dir="auto">Thanks. <img src="https://forums.opera.com/assets/plugins/nodebb-plugin-emoji/emoji/emoji-one/1f47d.png?v=qqje97jok90" class="not-responsive emoji emoji-emoji-one emoji--alien" title=":alien:" alt="👽" /></p>
]]></description><link>https://forums.opera.com/topic/4634/https-always</link><generator>RSS for Node</generator><lastBuildDate>Sun, 16 Aug 2026 01:20:41 GMT</lastBuildDate><atom:link href="https://forums.opera.com/topic/4634.rss" rel="self" type="application/rss+xml"/><pubDate>Fri, 22 Aug 2014 05:49:40 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to HTTPS Always on Thu, 28 Aug 2014 18:26:47 GMT]]></title><description><![CDATA[<p dir="auto"><img src="https://forums.opera.com/assets/plugins/nodebb-plugin-emoji/emoji/emoji-one/1f615.png?v=qqje97jok90" class="not-responsive emoji emoji-emoji-one emoji--confused_face" title=":/" alt="😕" /><br />
:faint:</p>
]]></description><link>https://forums.opera.com/post/48980</link><guid isPermaLink="true">https://forums.opera.com/post/48980</guid><dc:creator><![CDATA[[[global:former_user]]]]></dc:creator><pubDate>Thu, 28 Aug 2014 18:26:47 GMT</pubDate></item><item><title><![CDATA[Reply to HTTPS Always on Thu, 28 Aug 2014 17:35:06 GMT]]></title><description><![CDATA[<p dir="auto">Thanks digmed.  <img src="https://forums.opera.com/assets/plugins/nodebb-plugin-emoji/emoji/emoji-one/1f199.png?v=qqje97jok90" class="not-responsive emoji emoji-emoji-one emoji--up_button" title=":up:" alt="🆙" /></p>
<p dir="auto">Making all Opera-sites HTTPS by default is an ambitious plan, and it will take some time, I guess.</p>
<p dir="auto">Why not, as a small first step, remove the redirect to HTTP for <a href="http://forums.opera.com" target="_blank" rel="noopener noreferrer nofollow ugc">forums.opera.com</a>. <img src="https://forums.opera.com/assets/plugins/nodebb-plugin-emoji/emoji/emoji-one/1f609.png?v=qqje97jok90" class="not-responsive emoji emoji-emoji-one emoji--winking_face" title=";)" alt="😉" /></p>
]]></description><link>https://forums.opera.com/post/48976</link><guid isPermaLink="true">https://forums.opera.com/post/48976</guid><dc:creator><![CDATA[[[global:former_user]]]]></dc:creator><pubDate>Thu, 28 Aug 2014 17:35:06 GMT</pubDate></item><item><title><![CDATA[Reply to HTTPS Always on Thu, 28 Aug 2014 07:08:59 GMT]]></title><description><![CDATA[<p dir="auto">Making HTTPS available also when not signed in is a perfectly valid request. Unfortunately I can't promise this will be prioritized, but we will be looking into making all Opera sites HTTPS by default.</p>
]]></description><link>https://forums.opera.com/post/48919</link><guid isPermaLink="true">https://forums.opera.com/post/48919</guid><dc:creator><![CDATA[digmed]]></dc:creator><pubDate>Thu, 28 Aug 2014 07:08:59 GMT</pubDate></item><item><title><![CDATA[Reply to HTTPS Always on Wed, 27 Aug 2014 18:15:09 GMT]]></title><description><![CDATA[<p dir="auto">What's your problem?<br />
Really?<br />
Myself personally ain't got no prom with all that stuff your seem to be talking about.<br />
I blop a letter, the autofill autofills it to <code>forums.opera.com</code>, the [Overview] page loads, autoreloads to the signed-in state, https, I'm on "Overview", signed in, no prom, blah-blah, now you come, tell me as if "we all gonna die" - or what?<br />
What's the problem, dudes? <img src="https://forums.opera.com/assets/plugins/nodebb-plugin-emoji/emoji/emoji-one/1f642.png?v=qqje97jok90" class="not-responsive emoji emoji-emoji-one emoji--slightly_smiling_face" title=":)" alt="🙂" /></p>
]]></description><link>https://forums.opera.com/post/48877</link><guid isPermaLink="true">https://forums.opera.com/post/48877</guid><dc:creator><![CDATA[[[global:former_user]]]]></dc:creator><pubDate>Wed, 27 Aug 2014 18:15:09 GMT</pubDate></item><item><title><![CDATA[Reply to HTTPS Always on Fri, 22 Aug 2014 11:46:55 GMT]]></title><description><![CDATA[<p dir="auto">:rolleyes:  &lt;_&lt;</p>
]]></description><link>https://forums.opera.com/post/48460</link><guid isPermaLink="true">https://forums.opera.com/post/48460</guid><dc:creator><![CDATA[[[global:former_user]]]]></dc:creator><pubDate>Fri, 22 Aug 2014 11:46:55 GMT</pubDate></item><item><title><![CDATA[Reply to HTTPS Always on Fri, 22 Aug 2014 10:58:07 GMT]]></title><description><![CDATA[<ol>
<li>Making the secure connection available when not signed in does not make the insecure connection unavailable.</li>
<li>Clients that don’t support HTTPS also don’t support HSTS, so using that would not cause problems for those clients.</li>
<li>Tell those hoovers to get ready for HTTP/2 (<a href="https://http2.github.io/" target="_blank" rel="noopener noreferrer nofollow ugc">https://http2.github.io/</a>).</li>
</ol>
]]></description><link>https://forums.opera.com/post/48453</link><guid isPermaLink="true">https://forums.opera.com/post/48453</guid><dc:creator><![CDATA[[[global:former_user]]]]></dc:creator><pubDate>Fri, 22 Aug 2014 10:58:07 GMT</pubDate></item><item><title><![CDATA[Reply to HTTPS Always on Fri, 22 Aug 2014 08:54:57 GMT]]></title><description><![CDATA[<p dir="auto">Directly.<br />
If a hoover has an Opera installed, the forums should be readable - easily - from a hoover.<br />
Hoovers don't do hetepepese.</p>
]]></description><link>https://forums.opera.com/post/48450</link><guid isPermaLink="true">https://forums.opera.com/post/48450</guid><dc:creator><![CDATA[[[global:former_user]]]]></dc:creator><pubDate>Fri, 22 Aug 2014 08:54:57 GMT</pubDate></item><item><title><![CDATA[Reply to HTTPS Always on Fri, 22 Aug 2014 08:25:18 GMT]]></title><description><![CDATA[<ol>
<li>How is that relevant?</li>
<li>What is to like in it?</li>
</ol>
<p dir="auto">Thanks.</p>
]]></description><link>https://forums.opera.com/post/48448</link><guid isPermaLink="true">https://forums.opera.com/post/48448</guid><dc:creator><![CDATA[[[global:former_user]]]]></dc:creator><pubDate>Fri, 22 Aug 2014 08:25:18 GMT</pubDate></item><item><title><![CDATA[Reply to HTTPS Always on Fri, 22 Aug 2014 08:14:58 GMT]]></title><description><![CDATA[<p dir="auto">No.</p>
<ol>
<li>This is a technical support forum.</li>
<li>I like it the way it is.</li>
</ol>
]]></description><link>https://forums.opera.com/post/48446</link><guid isPermaLink="true">https://forums.opera.com/post/48446</guid><dc:creator><![CDATA[[[global:former_user]]]]></dc:creator><pubDate>Fri, 22 Aug 2014 08:14:58 GMT</pubDate></item></channel></rss>