This is a good change, reducing the incentive to create trusted certs for servers running on loopback. I'm happy to see Mozilla pushing it through!
Gecko: Intent to prototype & ship: Treat localhost addresses as "Potentially Trustworthy" groups.google.com/d/msg/mozi…
2
8
26
Is this why using Burp and similar proxies don’t work on localhost?
1
I'm not familiar enough with Gecko's internals to answer, unfortunately.
1
It’s Chrome where it doesn’t work (requires extra effort to configure around the proxy block). Works fine on Firefox, but guessing now that too will need the workaround.
1
Point me to a bug? I don’t think I understand the problem.
1
It’s not a bug, but a security feature apparently. I run into it because I teach hacking using Burp and Web Goat (running on localhost). Chrome doesn’t allow proxies on localhost by default.
1
Replying to @bilcorry @mikewest
I was asking about the reason behind the choice. Sorry, should have been more clear.

Oct 21, 2020 · 3:24 PM UTC

1
Replying to @bilcorry
If it's a network stack choice, @sleevi_ might have insight?
1