| ▲ | ywain 2 hours ago | |
The detailed terms of the bet include this: > A 301 redirect from www.longbets.org/601 to a different URL containing that text would also fulfill those conditions. I assume this would cover the HTTP->HTTPS redirect scenario. | ||
| ▲ | kijin an hour ago | parent | next [-] | |
I think the parent is referring to the possibility that one day, browsers might put up a blanket security warning for HTTP URLs instead of following redirects. Or they might try to be a little too clever with HTTPS upgrades. In particular, the automatic upgrade feature in modern browsers is based on several heuristics rather than explicit configuration like HSTS, so there's always a bit of room for breakage there. For example, they don't even check if the server returns a 301 redirect, which can be problematic if the server wants to redirect to HTTPS on a different host/port or make some changes to the path. | ||
| ▲ | oofbey an hour ago | parent | prev [-] | |
Yeah that was a clever bit of foresight there. | ||