5 ms·
Please petition GitHub to support HTTPS on GitHub pages
- zackify 11y agoBeen wanting built in ssl forever.
- detaro 11y agoWhat's missing in all that is that they are talking about HTTPS for custom domains, username.github.io supports HTTPS already.
- kevindeasis 11y ago+1 But are you guys seriously going to spam github/contact or support@github.com ? Because if that was my inbox. I'd be pissed looking at thousands of emails that contain the same body.
- KNoureen 11y agoMakes it super easy to filter out and delete though...
- jstoiko 11y agoMaybe let people star a dedicated repo instead of sending an email to github.
- leighmcculloch 11y agoYou can use CloudFlare with a custom domain in front of Github Pages. It works. I do this for https://github.com/leighmcculloch/5tweets.com https://github.com/leighmcculloch/5tweets.com which you can see SSL'd at https://5tweets.com https://5tweets.com.
- deleted 11y ago[deleted]
- rasz_pl 11y agoand doesnt work in older browsers - free cloudflare cert is ECDHE
- crymer11 11y agoAs some who cares both about accessibility on the web and security, what up-to-date browsers don't support ECDHE and what else would be reasonable to support as well?
- rasz_pl 11y agoprobably nothing up-to-date, hence I wrote older :) Opera 12.xx being one of the older browsers that works 99% of the time, except EVERY SINGLE page with Cloudflare cert What makes matters worse is CloudFlare lying about support level: https://support.cloudflare.com/hc/en-us/articles/203041594-What-browsers-work-with-CloudFlare-s-SSL-certificates- https://support.cloudflare.com/hc/en-us/articles/203041594-W... They claim Opera 8, 2005 browser supports ecdhe.
- russell_h 11y agoAt this point anyone using Opera 12.xx must have pretty low expectations of the web though, right? Even if it is really _only_ CloudFlare, they must be used to seeing that?
- rasz_pl 11y agoso far its only been hobby/torrent/scam sites using free cert, nothing you would hesitate opening in a webproxy. Ill switch browsers when I can open ~100 tabs without eating 8GB of ram (blink engine), Opera 12.17 does it at <2GB, not to mention being able to configure everything per domain (js,blockers,cookies etc).
- prdonahue 11y agoThat listed was originally created based on minimum requirements for SNI. I've gone through recently and documented where versions need to be adjusted "up" based on requirement for ECDSA support. These changes will be posted as part of some other housekeeping work I have planned for cloudflare.com/ssl.
- logical42 11y agoYeah but someone can still get between cloudflare and github pages since the traffic between the two end points would still be unencrypted and thus open to MITM..
- samwillis 11y agoActually GitHub have ssl on their username.github.io domain so you can have full ssl from cloudflair back to GitHub.
- sneak 11y agoWhich unfortunately doesn't work with CloudFlare on a different domain because it sends the custom domain Host header.
- prdonahue 11y agoYou can use a Page Rule to override this host header with whatever you like: https://support.cloudflare.com/hc/en-us/articles/206652947-Using-Page-Rules-to-Re-Write-Host-Headers https://support.cloudflare.com/hc/en-us/articles/206652947-U....
- sneak 11y agoEnterprise plans only. I thought "do all of this for free" was implicit in the request to GitHub.
- lucaspiller 11y agoActually Cloudflare supports SSL on the backend (as a paid feature) so the only place it could be MITMed is in their network. I'd still like to see it a bit stricter in that I can specify my own self-signed CA that they validate against. https://blog.cloudflare.com/introducing-strict-ssl-protecting-against-a-man-in-the-middle-attack-on-origin-traffic/ https://blog.cloudflare.com/introducing-strict-ssl-protectin...
- 11y ago
- elmin 11y agoThis is a little weird to me, because it's so easy to host your site a multitude of different ways. The notable thing about GH is its free, which makes complaining about it not having the one feature you want so odd. If you want that feature, pay the buck or two it will cost to host your site on CloudFront with something like Stout [1]. 1: http://stout.is http://stout.is
- SXX 11y agoYou can as well deploy on OpenShift. They provide 3 small gears for free and allow SSL for bronze accounts (require credit card info, but no payments until you go over free limit). https://www.openshift.com/ https://www.openshift.com/
- CamatHN 11y agoThats another thing to configure and worry about though, especially if its just for open source side projects which can be hard to justify spending $ on. Thats another service you have to monitor to see if its continuing, another service to be hacked, another account user/pass to have.
- mslate 11y agoIronically, Stout does not support SSL "out of the box": https://github.com/EagerIO/Stout#ssl https://github.com/EagerIO/Stout#ssl
- beefman 11y agoWhy is securing the web a hassle? Is it just that the certificate trust chain is so fluxored? (Crockford has an interesting perspective here in recent talks)
- bobfunk 11y agoWe provide both SNI based SSL (starting at $9 including the cert) and full SSL ($49) with CDN based hosting at https://www.netlify.com https://www.netlify.com As many other has noted, even when once in the future you'll be able to rely on free certificates from Let's Encrypt, serving millions of sites with different certificates (that needs to be replaced every 90 days) adds lots of complexity to any CDN based infrastructure and cost real money. Apart from that, if you do just SNI based SSL you have to add support costs for explaining to people that don't know the implications, why things like some automation tools, old Android browsers, IE on Windows XP, etc, breaks. And if you do full SSL you need to allocate lots of IP addresses at each CDN PoP which is expensive. The certificate is just a small part of the equation when you're offering CDN based SSL.
- joeyrideout 11y agoI agree with imbriaco's sentiment from the linked discussion - using a CDN or some other host that supports SSL to host your static site is a good solution. I recently migrated my GitHub pages site to Amazon S3 and Cloudfront. I had to buy a cheap Comodo SSL certificate and upload it to AWS to get it working with my custom domain, but the documentation[1] was good enough that it didn't take me very long at all. [1] http://docs.aws.amazon.com/AmazonCloudFront/latest/DeveloperGuide/SecureConnections.html#CNAMEsAndHTTPS http://docs.aws.amazon.com/AmazonCloudFront/latest/Developer...
- alaaibrahim 11y agoYeah, and please send me a free flying car while you are at it. Obviously everybody would like that, but it's not as easy as it seams. As github pages, technically are virtual domains, they share the same ip with many other pages, if you want to support https, you need to serve either each page on a different ip (not free), or they need a to configure multidomain ssls (which everytime they need to add a new domain, that means they have to reset the certificate for the other domains on the same ip), and I think there is a limit on the number of domains that can share the same ip - citation needed - . And all of this for free. Want SSL on gh pages, setup a proxy infront of gh pages.
- 0x0 11y agoOr you can use a web server that supports SNI. You'd lose android 2.x and ie@winxp clients though, but those will be lost anyways soon due to outdated cipher suites and certificate hash algorithms
- alaaibrahim 11y ago> configure multidomain ssls (which everytime they need to add a new domain, that means they have to reset the certificate for the other domains on the same ip), Sorry should've called it SNI.
- 0x0 11y agoMultidomain certs are not the same thing as SNI.
- alaaibrahim 11y agoThank you, learned something new today.
- byroot 11y agoNo, you also have SNI (Server Name Indication), it totally solve this problem. The only downside is that IE on Windows XP doesn't support it. But for a free service it's good enough.
- alfredxing 11y agoI'd love to see SSL support on custom domains as well, but I know there are a couple of reasons why it hasn't happened already: 1. GitHub Pages likely isn't a core focus for GitHub, however useful it may be 2. GitHub Pages is currently completely interface-less, relying only on an automated build system running each site through Jekyll and deploying it. In order to support custom certificates, they would need to build an interface for certificate uploading/maintenance (and of course putting the certs & keys into the repo, like the current CNAME system, won't work).
- landr0id 11y ago> In order to support custom certificates, they would need to build an interface for certificate uploading/maintenance With Let's Encrypt (mentioned in the issue) it could be 100% automated with free certs.
- lifthrasiir 11y agoIf there are hundreds of thousands of these certificates, you will need a custom ACME client anyway. It is not trivial even with a presence of SNI.
- diafygi 11y agoEh, ACME isn't that complex. I wrote a fully automated client in less than 200 lines of python. https://github.com/diafygi/acme-tiny https://github.com/diafygi/acme-tiny
- lifthrasiir 11y agoAn HTTP client that gives a simple automated response is easy to write. An HTTP client that gives simple automated responses to 10,000 connections every second is not easy to write. (Disclaimer: That said, I haven't seriously assessed the scalability of typical ACME clients. I would appreciate any hard number for them.)
- aritraghosh007 11y agoIts quite a co-incidence that I scouted for an answer for this today while I was setting up SSL for my gh-pages. As already pointed out by some comments, its not quite as simple as we think it is to have GitHub extend SSL for its pages. Its for the same reason that Tumblr doesn't allow SSL support for custom domain either. IMHO, CloudFlare is probably the simplest workaround to get SSL enabled for your gh-pages. Link on how to https://me.net.nz/blog/github-pages-secure-with-cloudflare/ https://me.net.nz/blog/github-pages-secure-with-cloudflare/
- stephentmcm 11y agoOf note guys there's a little ! icon button in the top of the page to report this gist. It's basically encouraging spam and as everyone has pointed out, is likely not technically sound.
- Sir_Cmpwn 11y agoI add SSL through a proxy to GitHub pages.
- ossreality 11y agoDing dongs that don't understand how SSL works. Just use Cloudflare and be done with it. It takes like 10 minutes to get a totally free self hosted blog with SSL. Except the price of the domain name, I guess.
- diafygi 11y agoFYI, when Let's Encrypt goes public in a week, you'll be able to get free certs without having to install anything by using https://gethttpsforfree.com https://gethttpsforfree.com Fun fact, the website is just a reverse proxied github static page: https://diafygi.github.io/gethttpsforfree https://diafygi.github.io/gethttpsforfree
- jakobegger 11y agoIsn't Github Pages hosted on S3? That would explain the lack of TLS on custom domains. Anyway, this is a very major security flaw. Lots of software uses Github pages for the project website. If you put a download link on an unsecure page, you are putting all your customers st risk.
- manigandham 11y agoGithug Pages is their own infrastructure for hosting files and static sites: http://githubengineering.com/rearchitecting-github-pages/ http://githubengineering.com/rearchitecting-github-pages/ Also the download files themselves can be hosted on Github repos as releases which supports TLS.
- jakobegger 11y agoHosting the downloads themselves via HTTPS is completely useless if the link to that file is transferred over HTTP.
- manigandham 11y agoLink to the repo/releases page...
- jakobegger 11y agoJesus Christ, you really don't understand, do you? If the original website is insecure, everything could be faked, including the link to the releases page. If HN readers don't understand this, who does?
- kentbrew 11y agoWorth noting: https works on yourname.neocities.org.
- detaro 11y agojust likes it does on yourname.github.io. (Since that just requires a wildcard cert)
- SamReidHughes 11y agoWhat's missing is, why? It's a static site, so you won't get any real privacy about what you're reading. If you have binaries to distribute, you have other features for releasing them that let you use TLS.
- manigandham 11y agoIt's a valid point as the content of the site itself can still be manipulated if not served securely. However that being said, it does seem like a very low risk situation and if needed there are tons of other options. Most of the Pages sites are just about projects themselves so the readme.md and wiki in the github repo can already serve over https and do the job just fine.
- sdrinf 11y agoScript injection (see Comcast a few weeks ago), page manipulation (eg. pointing at download links with malicious side-load), keyword-based filtering (HTTP inspection). If you're using non-default DNS servers, you also get privacy on which site you're reading: all HTTP request headers also get TLS protection, which includes hostname, path, etc. And while outside of Tor, there's no protection for the IP address (so third parties can know you're reading a page on github), "a site hosted on github" encompasses a wide variety of content.
- SamReidHughes 11y ago> "a site hosted on github" encompasses a wide variety of content. That doesn't help, you can easily fingerprint a page from secondary requests or incoming/outgoing links.
- detaro 11y agoAFAIK the hostname is not encrypted when using SNI
- Buge 11y agoWell in the past China has intercepted non-https connections and inserted malicious javascript that joined the users into a botnet that launched a DDOS attack on github. The "Great Cannon".
- fibo 11y agoI also have my personal website on GH pages + Cloudflare. If it is for a static web site I think it is ok, and thanks to both companies that gives us this service for free. If you pretend more you can pay and use AWS or some other service.
- bad_user 11y agoWhile GitHub has a free account, it gets quite expensive when you start paying. And GitHub Pages is a complementary add-on and many of us stayed on GitHub because of nice things like this. I do agree that it isn't their core focus and that people could host their stuff somewhere else for cheap. However there is something to be said about making encrypted connections the standard. Chrome and Firefox will only support encrypted HTTP 2.0 connections. So if GitHub Pages does not provide HTTPS for custom domains, then it won't support HTTP 2.0. Adding HTTPS support is also the right thing to do given the recent attacks on privacy. Yes, GitHub Pages is a free add-on that isn't their competency, but in my opinion they should either drop it completely, or support HTTPS. Because otherwise they are keeping the web back due to their popularity.
- deleted 11y ago[deleted]