Firefox 37 enables opportunistic encryption by default, encrypts HTTP connections over TLS
New Firefox version says “might as well” to encrypting all Web traffic — Ready or not, “opportunistic encryption” goes live. (Some configuration required.) — Developers of the Firefox browser …
Context & Ripple Effects
In 2015 this was the opening move of Mozilla's encrypt-by-default strategy: Firefox 37 wraps ordinary HTTP connections in TLS opportunistically, upgrading traffic to sites that never configured certificates themselves. A year later the idea proved contagious at infrastructure level, when [[a:874926|CloudFlare made opportunistic encryption, automatic HTTPS rewrites and TLS 1.3 default for its entire client base]].
Read against Mozilla's later playbook — blocking trackers by default in Firefox 69, rolling out encrypted DNS over HTTPS for US users, and switching on Total Cookie Protection — the 2015 change looks less like a feature drop than the first rung of a ladder where each default flips another channel of plaintext visibility away from network observers.
First-order effects
- HTTP-only websites suddenly serve Firefox users over encrypted connections without any server-side work, while passive eavesdroppers — ISPs, shared-network snoops — lose read access to that traffic.
Second-order effects
- CDN operators face user expectations set by the browser rather than by their own configs, a dynamic CloudFlare answered within a year by defaulting its whole client base onto opportunistic encryption and HTTPS rewrites.
Third-order effects
- If the default-flipping pattern holds — as Firefox 69, DoH and Total Cookie Protection suggest it did — browser vendors, not site operators or regulators, become the de facto arbiters of what stays visible on the wire, squeezing ISP-level observation out of the browsing path.
The trend: Browser makers are converting privacy protections from opt-in settings into shipped defaults, with each flip narrowing what network intermediaries can see.