Web sites shouldn't use the unsafe-url policy, as this tends to induce HTTPS URLs to generally be uncovered around the wire about an HTTP connection, which defeats one of many vital privacy and stability guarantees of HTTPS. This can be a disincentive emigrate to HTTPS, because it deprives connected HTTP http://XXX