Join GitHub today
GitHub is home to over 31 million developers working together to host and review code, manage projects, and build software together.
Sign upRebrand "Block all unencrypted requests" feature #16985
Comments
zoracon
added
the
enhancement
label
Oct 25, 2018
This comment has been minimized.
This comment has been minimized.
|
Part of my mental model for this: I would like to make it easy for people to contact website owners and say "Hi, your website doesn't work in HTTPS Everywhere's , please fix that." So it should be fairly short, sound very positive so the site owner is like "ooh yeah I should support that," and be reasonably self explanatory (though it will still need some explanation) |
This comment has been minimized.
This comment has been minimized.
|
I haven't given too much thought about it but what about "HTTPS only"? Although it may not be 100% technically accurate, that's probably the most intelligible option for non-technical users. I would be wary of phrases with "secure" because it may give the false (and already way too common) impression that the other party is trustworthy. For some reason, I like (1) and (2). I don't know why but "XXX-only" options sound better to me. Maybe because it's easier to understand even for non-native speakers (?) |
This comment has been minimized.
This comment has been minimized.
|
I just checked and Firefox uses "secure" for HTTPS (if click on the padlock), but for me security is not only HTTPS. |
This comment has been minimized.
This comment has been minimized.
|
HTTPSE do not block |
This comment has been minimized.
This comment has been minimized.
This comment has been minimized.
This comment has been minimized.
|
I'm going to give this till the end of the week until I call it for (2) Encrypted-Only Mode. |
This comment has been minimized.
This comment has been minimized.
|
Two more contenders: (6) Full Encryption Mode |
This comment has been minimized.
This comment has been minimized.
|
One thing that comes to mind is that Encrypted-Only Mode is abbreviated as EOM, which isn't great. |
This comment has been minimized.
This comment has been minimized.
|
In which case I think I'm leaning back towards Encryption Ensured Mode. EEM sounds kinda cool as an abbreviation too. If no one objects by the end of the day tomorrow let's go with EEM! |
This comment has been minimized.
This comment has been minimized.
|
After some internal discussions we've landed on "Encrypt All Sites," which is a reasonable simplification of what we're trying to do. This may lead some to think that even sites that don't have HTTPS will be encrypted, so we're going to include some question-mark in a circle or other tooltip helper to explain exactly what Encrypt All Sites mode does. |
This comment has been minimized.
This comment has been minimized.
|
Drafting some tooltip text: "This will block all unencrypted connections from being made in your browser, and attempt to upgrade all site visits to HTTPS. Sites that do not support HTTPS will not be upgraded, but you will be given the option to disable HTTPS Everywhere for these sites if you wish to access them insecurely." |
This comment has been minimized.
This comment has been minimized.
|
I think this is good, but we can remove the "block" language since that's explained clearly later in the statement: "This will attempt to upgrade all requests to HTTPS. Sites that do not support HTTPS will generate an error, but you will have the option to bypass the error for specific sites." |
This comment has been minimized.
This comment has been minimized.
|
I like "Encrypt All Sites Eligible" since it provides the context to these user that we will enforce encryption when available and the tool tip will answer the question of what happens when it is not. |
This comment has been minimized.
This comment has been minimized.
|
Plus the acronym is "EASE" which is pretty nice! |
This comment has been minimized.
This comment has been minimized.
dr-1
commented
Feb 19, 2019
|
I find "Encrypt All Sites Eligible" confusing (eligible how?). Landed here when trying to find out what's going on with that. Some of the other suggestions above, and even the original phrase, were clearer in my opinion. |
This comment has been minimized.
This comment has been minimized.
|
Thanks for the feedback, @dr-1! Is it particularly the "eligible" part you find confusing? I.e. would "Encrypt All Sites" be clearer? |
This comment has been minimized.
This comment has been minimized.
dr-1
commented
Feb 20, 2019
|
Yes, "eligible" sounds like the plugin applies some selection criteria to decide whether encryption is used, whereas what this option really does is insist on HTTPS for all connections, if I understand correctly. "Encrypt All Sites" can also lead users to think that the plugin is doing its own encryption, and doing it on all sites regardless of how they are set up. Of course they'll find out that's not the case when an error message comes up about HTTPS being unavailable on a particular site, but why not describe it more accurately from the start. "Block All Unencrypted Requests" said it all. I think "Encrypted-Only Mode", "Encryption Ensured Mode" or "HTTPS Only" do, too. |
This comment has been minimized.
This comment has been minimized.
thwaller
commented
Feb 26, 2019
|
I also landed here in effort to learn what "Encrypt All Sites Eligible" means and does. Oddly, there seems to be no documentation anywhere that explains this in any way. I agree that the ability to say/use "EASE" is nice, but in this case "Block all unencrypted requests" would not have required me to seek a meaning of the feature. I would personally opt for the old name as it was clear, the new is not clear. |
This comment has been minimized.
This comment has been minimized.
|
@thwaller thanks for the feedback! We're in the middle of an entire extension redesign, which will include a tooltip |
This comment has been minimized.
This comment has been minimized.
thwaller
commented
Feb 26, 2019
|
@Hainish thanks for the reply. Aside from the tooltip idea, what I was looking for is a getting started type of screen, whether in/from the app or on your web site. Obviously in the app would be ideal, but it would be easier, and faster, to add a segment to the web site. Thanks for the work on this. |

Formed in 2009, the Archive Team (not to be confused with the archive.org Archive-It Team) is a rogue archivist collective dedicated to saving copies of rapidly dying or deleted websites for the sake of history and digital heritage. The group is 100% composed of volunteers and interested parties, and has expanded into a large amount of related projects for saving online and digital history.

Hainish commentedOct 25, 2018
Type: other
"Block all unencrypted requests" is a phrase which is overly verbose and hard to reference. We keep on using the BAUR initialism when we don't want to type it out.
I suspect this feature will be used more and more as the web gets better and better HTTPS coverage. To make this feature easily referenceable and neater, I propose we rebrand it to something a bit nicer.
In the past we've used the phrase "HTTP Nowhere Mode", but this isn't properly descriptive since this mode blocks FTP connections now as well.
We will do some user testing on what makes the most intuitive sense for this feature, but I'd like to throw a few options out and see if they float or swim.
Before coming up with other options, I was leaning towards (1) as a personal preference. But listing out these options, I actually like (5) the best. Next to any of these options in the drop-down, I'd like some help bubble text saying "This blocks all unencrypted requests" or something that better explains what this does.
cc @zoracon @J0WI @Bisaloo @cschanaj