Opened 5 years ago

Last modified 4 years ago

#8653 assigned enhancement

Implement an efficient form of simple ruleset for domains that Just Work™ in https

Reported by: pde Owned by: micahlee
Priority: Medium Milestone: HTTPS-E 4 stable
Component: HTTPS Everywhere/EFF-HTTPS Everywhere Version:
Severity: Keywords: gsoc2013
Cc: MB Actual Points:
Parent ID: Points:
Reviewer: Sponsor:


MB asked me for this a while ago. It would help incrementally with the RAM consumption and startup latency issues that we have with some domains.

It could be implemented by just sticking the domain in the HSTS preload list, or by emulating that behaviour using our existing API hooks.

Child Tickets

Change History (5)

comment:1 Changed 5 years ago by pde

This probably needs to be done simultaneously in Chrome and Firefox, so that the ruleset library can be remain the same in both, unless there's a way to automatically classify these "simple" rulesets at build time.

comment:2 Changed 5 years ago by pde

Milestone: HTTPS-E 4 stable

Let's try to land this at some point before 4.0 stable in order to reduce the startup overhead and RAM consumption that will come with those thousands of extra rulesets.

comment:3 Changed 5 years ago by pde

Owner: changed from pde to micahlee
Status: newassigned

comment:4 Changed 5 years ago by pde

Keywords: gsoc2013 added

Well I just assigned this to Micah but actually this would make a good first project for a hypothetical GSOC intern.

comment:5 Changed 4 years ago by zyan

It seems that the tricky part of this is detecting which rules "just work". Seth attempted to write a script to do this, but it only found about 100 domains. Once that is done, it's not hard to use the HSTS mechanism.

Note: See TracTickets for help on using tickets.