In a groundbreaking statement earlier this week, Mozilla announced that all web-based features included in Firefox in the future must only be served over a secure HTTPS connection.
This means that if Firefox adds support for a new feature that makes communications between the browser and an external server, those communications will ONLY be made over HTTPS or it will not support them. The move comes after a continued push from browser makers to force website owners and developers to adopt secure connections as the default mode for their websites.
Nearly 65% of websites loaded by Firefox in November 2017 used HTTPS, up from 45% at the end of 2016, according to the Let's Encrypt Project. Google, on the other hand, has never announced a rule that all new features must work over a secure connection, but its engineers are building new features and functionality for Chrome that only work in a secure environment.
In addition to enforcing an HTTPS-only rule, Mozilla also wants to encourage web developers to pay more attention to security. Therefore, Mozilla plans to add developer tools in future versions of Firefox to allow testing of connections with and without HTTPS. This will help developers develop HTTPS-friendly websites and applications even for legacy features (WebVR, API Payment Request, etc.).
