# Make Case 491 "Bad"

**URL:** <https://tosdr.community/t/make-case-491-bad/3359>\
**Category:** Case Discussions\
**Created:** [March 31, 2025, 6:24pm UTC](https://tosdr.community/t/make-case-491-bad/3359 "2025-03-31T18:24:16Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Deveroonie](https://tosdr.community/user_avatar/tosdr.community/deveroonie/32/1863_2.png) [@Deveroonie](https://tosdr.community/u/Deveroonie)\
**Post date:** [March 31, 2025, 6:24pm UTC](https://tosdr.community/t/make-case-491-bad/3359/1 "2025-03-31T18:24:16Z")

</div>

I don’t believe Case 491 - All Traffic is unencrypted (no https) - should be a blocker, as compared to others it isn’t that bad - while not ideal, it isn’t a dealbreaker.

> **[Terms of Service; Didn't Read - Phoenix](https://edit.tosdr.org/cases/491)**
>
> I have read and understood the terms of service is the biggest lie on the Internet. We aim to fix that.

---

<div class="post-metadata">

**Author:** ![shadowwwind](https://tosdr.community/user_avatar/tosdr.community/shadowwwind/32/1749_2.png) [@shadowwwind](https://tosdr.community/u/shadowwwind)\
**Post date:** [March 31, 2025, 7:24pm UTC](https://tosdr.community/t/make-case-491-bad/3359/2 "2025-03-31T19:24:11Z")

</div>

Strongly disagree. plain Text is susceptible to all kinds of man in the middle attacks, injections and tracking. Even worse for websites that transmit PII or passwords. TLS certificates are free now, there is absolutely no reason why an application/website that connects to/from the internet should use plain text http.

Additionally the point is very rare, which is exactly what a blocker should be.

See this post/video by Troy Hunt [Troy Hunt: Here's Why Your Static Website Needs HTTPS](https://www.troyhunt.com/heres-why-your-static-website-needs-https/)

---

<div class="post-metadata">

**Author:** ![Deveroonie](https://tosdr.community/user_avatar/tosdr.community/deveroonie/32/1863_2.png) [@Deveroonie](https://tosdr.community/u/Deveroonie)\
**Post date:** [April 4, 2025, 9:58pm UTC](https://tosdr.community/t/make-case-491-bad/3359/3 "2025-04-04T21:58:33Z")

</div>

I feel like it’s only rare because it’s never brought up, as opposed to it never happening.

---

<div class="post-metadata">

**Author:** ![shadowwwind](https://tosdr.community/user_avatar/tosdr.community/shadowwwind/32/1749_2.png) [@shadowwwind](https://tosdr.community/u/shadowwwind)\
**Post date:** [April 5, 2025, 7:49am UTC](https://tosdr.community/t/make-case-491-bad/3359/4 "2025-04-05T07:49:52Z")

</div>

2.4% according to Mozilla [The Evolution of HTTPS Adoption in Firefox | Attack & Defense](https://attackanddefense.dev/2025/03/31/https-first-in-firefox-136.html)

---

<div class="post-metadata">

**Author:** ![Dr\_Jeff](https://tosdr.community/user_avatar/tosdr.community/dr_jeff/32/2728_2.png) [@Dr\_Jeff](https://tosdr.community/u/Dr_Jeff)\
**Post date:** [February 20, 2026, 10:37pm UTC](https://tosdr.community/t/make-case-491-bad/3359/5 "2026-02-20T22:37:56Z")

</div>

I too disagree with increasing the score penalty. Browsers, I’d like to believe, are already configured out of the box to prompt the user for entering an `http://` site, if I’m not wrong.

---

<div class="post-metadata">

**Author:** ![Dr\_Jeff](https://tosdr.community/user_avatar/tosdr.community/dr_jeff/32/2728_2.png) [@Dr\_Jeff](https://tosdr.community/u/Dr_Jeff)\
**Post date:** [July 5, 2026, 7:27pm UTC](https://tosdr.community/t/make-case-491-bad/3359/6 "2026-07-05T19:27:45Z")

</div>


