Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Baidu will serve the script over HTTPS (though firefox complained about a bad certificate), the issue is that it will also serve it over HTTP, and some 3rd party pages request the HTTP version.


No browser will load the script from within a <script> tag because of the bad certificate, serving the script with a bad certificate achieves nothing.


The whole point is that the pages being modified are served over HTTP, there's no certificate there, good or bad.


The whole point is that you couldn’t use the script over HTTPS even if you really wanted to.


Oh okay I see what you mean now, sorry for the misunderstanding.




Consider applying for YC's Winter 2026 batch! Applications are open till Nov 10

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: