[HTTPS-E Rulesets] Suggested ruleset for new HTTPS site

Daniel Kahn Gillmor dkg at fifthhorseman.net
Thu Feb 5 14:11:40 PST 2015


On Thu 2015-02-05 13:42:55 -0500, Seth David Schoen wrote:
> In the past I had a script to autogenerate rules from the preload list,
> but I think we decided that it was redundant because the browsers we
> support now all use that list.  I don't think we've thought about the
> effect for folks (maybe like DuckDuckGo?) who use the rulesets for
> other purposes.
>
> Maybe we should just annotate the rulesets somehow and say "if you're
> using this for rewriting URLs outside of a browser, PLEASE also use the
> HSTS preload list for more comprehensive rewriting".

That's certainly the easiest way to proceed.  If you made that note
available with the script to autogenerate rules from the preload list
(so that folks could invoke it themselves if they were using it outside
of a browser), then i'd say that's a pretty good solution.

   --dkg


More information about the HTTPS-Everywhere-Rules mailing list