Background:
Vanadium currently inherits Chromium's "Always use secure connections" (HTTPS-First Mode) feature. When enabled, it attempts to upgrade all navigations to HTTPS. If a site does not support HTTPS or presents an invalid certificate, an interstitial warning is displayed.
However, this interstitial currently includes a "Continue to site" (click-through) button, allowing users to bypass the warning and proceed over an insecure connection.
Threat Model / Motivation:
For users with elevated threat models, allowing a manual bypass is a significant risk. In active MITM (Man-in-the-Middle) scenarios, SSL stripping or downgrade attacks, warning fatigue or social engineering can lead a user to accidentally click "Continue."
Currently, only sites with HSTS (via response headers or the preload list) prevent this user bypass (hard-fail). We can extend this hard-fail protection to all domains client-side.
Proposed Solution:
Introduce a strict toggle (e.g., "Strict HTTPS-Only Mode" or a sub-setting under "Always use secure connections") in Vanadium.
When enabled, the browser should apply HSTS-like semantics to all domain navigations:
- All requests are upgraded to HTTPS.
- If the HTTPS connection fails, or presents a certificate error, it results in a fatal error page with no bypass option (no "Continue to site" button).
To maintain basic usability for local networking (which is standard behavior for such security features), the following should be exempt from the strict blocking and allowed to proceed over HTTP:
- Localhost (localhost, 127.0.0.1, ::1)
- Raw IP addresses (especially RFC 1918 private IPs, commonly used for router/IoT admin panels).
Thank you for considering this enhancement for high-risk profiles!
Background:
Vanadium currently inherits Chromium's "Always use secure connections" (HTTPS-First Mode) feature. When enabled, it attempts to upgrade all navigations to HTTPS. If a site does not support HTTPS or presents an invalid certificate, an interstitial warning is displayed.
However, this interstitial currently includes a "Continue to site" (click-through) button, allowing users to bypass the warning and proceed over an insecure connection.
Threat Model / Motivation:
For users with elevated threat models, allowing a manual bypass is a significant risk. In active MITM (Man-in-the-Middle) scenarios, SSL stripping or downgrade attacks, warning fatigue or social engineering can lead a user to accidentally click "Continue."
Currently, only sites with HSTS (via response headers or the preload list) prevent this user bypass (hard-fail). We can extend this hard-fail protection to all domains client-side.
Proposed Solution:
Introduce a strict toggle (e.g., "Strict HTTPS-Only Mode" or a sub-setting under "Always use secure connections") in Vanadium.
When enabled, the browser should apply HSTS-like semantics to all domain navigations:
To maintain basic usability for local networking (which is standard behavior for such security features), the following should be exempt from the strict blocking and allowed to proceed over HTTP:
Thank you for considering this enhancement for high-risk profiles!