Skip to content

[Enhancement Request] "Strict / No-Bypass" toggle for HTTPS-First Mode (Apply HSTS semantics globally) #878

Description

@lingyicute

Background:

Vanadium currently inherits Chromium's "Always use secure connections" (HTTPS-First Mode) feature. When enabled, it attempts to upgrade all navigations to HTTPS. If a site does not support HTTPS or presents an invalid certificate, an interstitial warning is displayed.

However, this interstitial currently includes a "Continue to site" (click-through) button, allowing users to bypass the warning and proceed over an insecure connection.

Threat Model / Motivation:

For users with elevated threat models, allowing a manual bypass is a significant risk. In active MITM (Man-in-the-Middle) scenarios, SSL stripping or downgrade attacks, warning fatigue or social engineering can lead a user to accidentally click "Continue."

Currently, only sites with HSTS (via response headers or the preload list) prevent this user bypass (hard-fail). We can extend this hard-fail protection to all domains client-side.

Proposed Solution:

Introduce a strict toggle (e.g., "Strict HTTPS-Only Mode" or a sub-setting under "Always use secure connections") in Vanadium.

When enabled, the browser should apply HSTS-like semantics to all domain navigations:

  • All requests are upgraded to HTTPS.
  • If the HTTPS connection fails, or presents a certificate error, it results in a fatal error page with no bypass option (no "Continue to site" button).

To maintain basic usability for local networking (which is standard behavior for such security features), the following should be exempt from the strict blocking and allowed to proceed over HTTP:

  • Localhost (localhost, 127.0.0.1, ::1)
  • Raw IP addresses (especially RFC 1918 private IPs, commonly used for router/IoT admin panels).

Thank you for considering this enhancement for high-risk profiles!

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Fields

    Priority

    None yet

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions