Firefox 92 will block HTTP downloads on HTTPS pages by default
Firefox developers plan to block unsecured downloads on all HTTPS pages. Similar functionality was implemented in Google Chrome last year. It is also known as a mixed content download blocker.
When you visit an HTTPS page, you expect all information you submit to the site to be secured in transit. However, sites using HTTPS can link to regular HTTP resources. For example, links can lead to the download of any files. As a result, a user can accidentally connect to a site that is susceptible to attacks from people with poor intentions.
With the release of Firefox 92, users will be warned that they are downloading content from an unsecured source. Users can continue downloading files if they trust the site.
According to the existing roadmap, Firefox 92 is due to be released on 7 September. However, the innovation is already available in experimental releases of Firefox (Beta 92). You can enable it by going to about:config and setting the dom.block_download_insecure flag to true.
Subscribe to our updates to keep up with the latest news from the world of SSL!