brave / brave-browser

Brave browser for Android, iOS, Linux, macOS, Windows.
https://brave.com
Mozilla Public License 2.0
17.63k stars 2.3k forks source link

Crypto domains should be exempted from automatic HTTPS upgrades #33608

Open fmarier opened 11 months ago

fmarier commented 11 months ago

Brave supports a number of crypto domain name systems both for Wallet, but also for navigations via the URL bar or links.

These domains are unlikely to be able to acquire valid HTTPS certificates. Therefore we should disable automatic HTTPS upgrades for them.

fmarier commented 11 months ago

@arthuredelstein Feel free to close if we already exclude these TLDs.

arthuredelstein commented 11 months ago

These aren't explicitly excluded, but it may be that they already fall back automatically to HTTP. We should test what the current behavior is.