• maniel
    arrow-up
    24
    arrow-down
    0
    ·
    6 months ago
    link
    fedilink

    Another security feature added is the blocking of downloading files from URLs that are on lists of potentially dangerous content.

    Yeah, I’m not sure blocking HTTP downloads by default is a good idea, I mean many offices probably have some internal legacy HTTP only sites that nobody dares to touch, that are perfectly safe being HTTP (if you have hackers inside your network a simple intranet site spoofing is your least problem), and disabling this security option might have a lot of wider repercussions

    • emptiestplace
      arrow-up
      15
      arrow-down
      2
      ·
      6 months ago
      link
      fedilink

      I get it, but you’re arguing in favour of negligent IT. If nobody dares to touch something, it is a liability.

      • embed_me
        arrow-up
        7
        arrow-down
        2
        ·
        6 months ago
        link
        fedilink

        I would say he’s arguing in favour of practicality

        • emptiestplace
          arrow-up
          4
          arrow-down
          5
          ·
          6 months ago
          link
          fedilink

          There’s no good reason to be using :80 even internally.

    • noobnarski
      arrow-up
      5
      arrow-down
      0
      ·
      6 months ago
      link
      fedilink

      Edge has started doing that too, whenever I download something from my Home Assistant instance while at home I have to rightclick and say that I really want to download it.

      As long as such an option is available its not too bad.

      • maniel
        arrow-up
        4
        arrow-down
        0
        ·
        6 months ago
        link
        fedilink

        It’s not just about that, people will be disabling the feature that is potentially beneficial to their security, disabling http downloads from http sites is just an extension of blocking http downloads from https sites