20 ms·
Google Will Soon Shame All Websites That Are Unencrypted
- mc_hammer 11y agobingo check and mate TLS Certificate MITM Is now the fucking de-facto crypto thats the end of the story as far as ssl/tls security goes.. you wont hear about it anymore. and if you dont have it you are not trustworthy. thats it. no objections. no court hearing. youre just done. (its probably a good time to bring up the W3C president states this is not https3 this is tls labeled as https. and the 4 show stopping bugs tls has had so far. the downgraded exploitable encryption for other countries. the noob crypto bugs like null nonce/reusing nonce and the other one i forget, the authors published MITM kit, or the open bug for 1 year in usersupplementaldata for a buffer overflow, and how the heartblood code was using variables 'payload' not 'buf' or 'msg' but you know those were already downvoted -15 on HN. could also bring the fact they pushed this into all the popular ssh clients and the ssl, and IRC, so now they are capturing way more ssh, irc, and ssl.)
- 0x4a42 11y agoSorry?
- mc_hammer 11y agoanyone who does drugs could be a serial killer!! you are not safe to try any other drugs!! here inject these mercuries and aluminumummies!! for your safety we have hidden all posts below the bernie sanders TLS threshold
- mc_hammer 11y agothe downgraded to exploitable crypto for foreign countries this is for tor, this is for tor servers scattered across the globe
- Someone1234 11y agoThis is how it always should have been. It was mind boggling that mixed content was "insecure" but HTTP was "secure." HTTP is and always has been insecure and should be marked as such. I know there are a few people who will moan and groan about how overkill HTTPS is, but this isn't about banning HTTP it is just about reminding users that they shouldn't be entering sensitive information into a HTTP site. Even phishing sites should be DV secure.
- yeukhon 11y agoMixed content is insecure because of active content to be very honest. Most people don't care about passive, but of course, you can make some fake banner if you are able to MiTM. You'd like javascript coming from HTTPS rather than HTTP. HTTP itself is insecure but doesn't mean every website has to be over HTTPS. However, given HTTPS is cheaper to deploy it should be encouraged. Do I really need HTTPS to show an album of cat photos I share with the world? No. But I do anyway. However, the biggest challenge is actually internal traffic are almost always over HTTP, and the reason is almost always "because self-signed cert is invalid." In some way this is okish since internal traffic is a darknet, but as we have proper toolset make Let's Encrypt available, more people should consider deploying full SSL support for internal traffic as well. At this point, the toolchain to actually make Let's Encrypt simple and useful is still, ugh, a little hackish. Cron job here and there. Sort of complicated process to get started...
- mhurron 11y agoHTTP was never marked as secure. Mixed content was marked insecure because there were assets on the page that might not be from where you think they were from. It was an indicator that the little https lock in the URL bar wasn't telling you the whole story.
- ethbro 11y agoI think this is at the core of Google's thinking on this: unless presented with a negative, users' assumptions are that they're secure. Which is fair, given that I bet you'd get about a 5% or less recognition rate if you polled a random sampling of people on whether they could define "HTTPS" / "SSL" / "TLS" / "That lock thingie" to any degree of accuracy. A server shouldn't have the opportunity to serve an insecure connection to the user without the user being made explicitly aware of that fact.
- shostack 11y agoIs there a strategic business reason for this on Google's part other than a safer web is better for all? I don't doubt that a more secure web is better for everyone, I'm just more curious about the business drivers of this from their perspective. The reason I'm wondering is because with AMP, there seems to be a clear strategic benefit from having all of that ad serving data running through them even if the advertisers and publishers are not using the DoubleClick stack or Google Analytics. By bringing this to market from the standpoint of "improving" the mess publishers have brought upon themselves and speeding everything up, there's definitely a clear win for consumers here. That said, it leaves the door open for something similar to mobilepocolypse where Google updated their ranking signals on mobile to significantly favor mobile-friendly sites. I could easily see this going a similar route where it is a suggestion...until its not because if you don't implement it you'll lose rankings and revenue (and coincidentally feed Google all of your ad serving data in the process). To be clear, I don't knock them for taking this approach, because if it works it is a very smart business move that will be beneficial to a lot of parties (not just Google). Just looking for other insights into the business strategy behind something like pushing for encryption, and AMP.
- jimrandomh 11y ago> Is there a strategic business reason for this on Google's part other than a safer web is better for all? The two common reasons for MitM are spying and inserting/replacing advertisements. The latter is stealing from Google, so they want to stop it before it grows too common.
- kuschku 11y agoWe can only wonder how long it will be until Google starts openly advertising and buying newspaper articles against that new ad-replacing browser.
- Zikes 11y agoI think it's pretty funny that on the HN front page right now is a NYTimes article from the company's Google beat reporter about how trying to interview Larry Page is "emasculating" and then this announcement is accompanied by an image "shaming" the NYTimes web site for being unencrypted. As to the feature itself, I don't think it's a big deal at all. We all know that the average internet denizen doesn't understand HTTPS at all and would just as likely ignore it as anything. The only people that would see and understand this new red X for what it represents would know that it doesn't really matter that the lolcat meme they just downloaded came through an unsecured channel.
- civilian 11y agoI work for a SaaS company, we absolutely have customers who email us complaining about putting credit cards in a page served over http.
- Zikes 11y agoCertainly, and I would be one of them. I'm not saying nobody does care or that nobody should, only that enough people don't care enough to make this "red X of shame" that shameful, really. Chrome and Firefox have both had to take extreme measures for very similar things, such as web sites using expired (or even unvalidated/spoofed) SSL certificates. Google even reported that using a giant red page with warning labels didn't stop people from clicking through!
- civilian 11y agoRight, and I guess I meant to imply that it is some of the unwashed non-elite masses that notice that stuff. Our product is for people who are bad at software and want an easier way to do task X, but they still know to look for the green lock. I don't have strong data but I'd just say-- don't underestimate the web knowledge of people who are mostly making cat pictures.
- dorianm 11y agoYes! Funnily enough, the site this story is hosted on is using HTTP.
- dawnerd 11y agohttps://motherboard.vice.com/read/google-will-soon-shame-all-websites-that-are-unencrypted-chrome-https https://motherboard.vice.com/read/google-will-soon-shame-all... They should have it force https.
- josteink 11y agoYeah. Still not paying for a cert on my person home-pages just so I can have my own page come up first when people google my (worldwide unique) name. That page contains static HTML and does not need SSL, and it's not "insecure" just because you may be on a network which MITMs traffic. That makes your network insecure, not my page. So yeah. Not interesting. Not worth it.
- gilrain 11y agoJust set mine up for free, today. Letsencrypt.org works great. I recommend the simp_le client.
- dawnerd 11y agoYeah, there's really no excuse anymore really. They've made it insanely easy to generate certs.
- Cpoll 11y ago> That makes your network insecure, not my page. At which hop does it stop being "my" network and starts being "our" network? Your webhost? Your IX? Your country? You can't shift the responsibility; only you can definitively secure the content coming out of your webpage.
- serge2k 11y ago> Still not paying for a cert on my person home-pages lets encrypt?
- josteink 11y agoThat means moving to a webhost and plan which supports SSL. They are usually more expensive. It's not just getting the cert.
- kpcyrd 11y agoPlease read the article, this isn't about google the search engine, it's about google the browser vendor. Firefox nightly is doing the same already by default. I'm always wondering if there's a correlation between the relevance of integrity for a site and the relevance of the site itself.
- tacos 11y agoCue the sound of 100,000 static-hosted S3 bloggers grabbing their free Amazon SSL cert and setting up CloudFront. And man that AWS console sure is wonky.
- chatmasta 11y agoI tried setting up SSL with Cloudfront yesterday and it was a complete mess. The validation method is sending an email to the domain contacts as listed in whois. So if you have whois privacy enabled, you cannot receive the email and therefore cannot setup the cert. This is definitely a bug, because the system supposed to also send emails to admin@domain.com, hostmaster@domain.com, and a few others. With whois privacy enabled, I never received any of those emails. Even with whois privacy, you are supposed to be able to receive an email via the privacy registrar's proxy email... but Amazon parses it incorrectly and ends up sending the email to legal@whoisproxy.com I'm not the only one: https://forums.aws.amazon.com/thread.jspa?messageID=698280&tstart=0 https://forums.aws.amazon.com/thread.jspa?messageID=698280&t... https://forums.aws.amazon.com/ann.jspa?annID=3510 https://forums.aws.amazon.com/ann.jspa?annID=3510
- dude01 11y agoSounds good. I wonder when Google Cloud Storage will start supporting https on static websites hosted through them: https://cloud.google.com/storage/docs/website-configuration?hl=en https://cloud.google.com/storage/docs/website-configuration?... If they don't then they're not keeping up with hosting on Amazon's S3, which does support it.
- mikecb 11y agoSimilar (very, since appengine static files are served from GCS), is to write a "python" appengine yaml file that only serves the static content with secure: always.
- tomjen3 11y agoThey should do something useful for the web and remove most if not all the current root certificates. There are so many places that have what is essentially a master key to the internet - and that master key is only going to be more important as more and more sites become SSL.
- airswimmer 11y agoI think 80% of web sites will be labelled as red-unsafe. SSL layer security is good but sometimes a certificate is expensive and not free. Suppose that you have 10 domains and not all of them are for SNS, banks and etc.. At what minimum cost will you purchase a HTTPS certificate?
- pmlnr 11y agonada. http://letsencrypt.org/ http://letsencrypt.org/
- bcg1 11y agoMost shared hosting accounts charge extra for a dedicated IP address, both for setup and on a monthly basis. Don't underestimate how many blogs, churches, small businesses, etc still use services like that. To be fair, many of those sites probably ARE insecure, but it seems to be a little bit overkill to "shame" them for not implementing encryption.
- schoen 11y agoYou only need a dedicated IP address for clients that don't support SNI. If your hosting model supports it, you can also still support these clients with a single IP address with a SAN cert that includes all of the possible hostnames.
- JoshTriplett 11y agoSSL hasn't required a separate IP since Windows XP. And XP no longer has any security support, so anyone running it has bigger problems.
- bcg1 11y agoGuess you're right, fair enough. I still don't agree with putting a scarlet letter on these types of sites though.
- 11y ago
- SanderMak 11y agoSo is there already a solution for https on Github Pages with a custom domain?
- iancarroll 11y agoCloudFlare works best.
- bobfunk 11y agoCheck out netlify (https://www.netlify.com https://www.netlify.com) - we're like GitHub Pages on steroids (integrated continuous deployment, proxying, redirect and rewrite rules + lots of other features) and we launched free SSL on custom domains a couple of weeks ago :)
- JangoSteve 11y agoIn addition to CloudFlare, you can also use AWS CloudFront for this. We just implemented this to get https working on our custom-domain Github Pages site [1] this week. You first have to upload your SSL certificate to AWS IAM [2] (you only have to do this once, or you can just purchase your certificate from the AWS console now too). Then, all you have to do is create a new CloudFront distribution and point the origin to your subdomain.github.io URL and select your SSL certificate from the drop-down, then point your CNAME record to the CloudFront distribution. [1] https://os.alfajango.com/ https://os.alfajango.com/ [2] https://bryce.fisher-fleig.org/blog/setting-up-ssl-on-aws-cloudfront-and-s3/ https://bryce.fisher-fleig.org/blog/setting-up-ssl-on-aws-cl...
- tdkl 11y agoStumbled upon Kloudsec here on HN couple days ago [1] and gave it a go. The dashboard is a bit clunky where you kinda have to figure out what to do, but HTTPS works without needing to move the DNS to them, as in case of Cloudflare (which costs 20$ when moving from Gandi). Basically register account, enter your domain, update your DNS records with an A (replacing the Github pages IP) and TXT record (for verification). While the change in DNS was in couple minutes on Gandi, Kloudsec DNS took an hour or two to register the change. After that, you go in the "Security plugin" and enable it. If you're using an apex domain, you can remove the www. HTTPS request, since you won't get the cert for that (if you do have an apex domain then you probably know about the CNAME trick on Pages, unless your DNS provider supports ANAME or ALIAS records for the apex domain - Gandi doesn't). It took couple hours again to get the cert. When it's done click on the "Settings" cog icon for the desired HTTPS domain and enable HTTP-> HTTPS redirect and HTTPS rewrite, then you're set. [1] https://kloudsec.com https://kloudsec.com
- Theodores 11y agoJust enabled Chrome to show the little crosses by default for http:// http:// and I already like having this showing. If you wish to be an early adopter go to: chrome://flags/#mark-non-secure-as It is good to see how sites that matter are mostly https:// https:// already for me. The http:// http:// tabs I have open such as this article actually are insecure when you think about the amount of trackers on them, so the 'x' is very apt.
- bhartzer 11y agoFor Google, it’s not just about providing a secure environment and secure websites. In fact, Google actually has a monetary incentive to get as many websites to move over to HTTPs as possible: convincing website owners to move to HTTPs will help get rid of competing ad networks.
- aembleton 11y agoHow does it get rid of competing ad networks? Does Google have a monopoly on serving ads over HTTPS?
- callahad 11y agoIt means your internet provider can't inject ads or profile you based on the content of the sites that you visit. Comcast, AT&T, and Verizon have all done similar: https://certsimple.com/blog/ssl-why-do-i-need-it#4-not-having-your-content-modified-by-carriers https://certsimple.com/blog/ssl-why-do-i-need-it#4-not-havin...
- eyuelt 11y agoSure they can. Your ISP can easily MitM you.
- CydeWeys 11y agoNot without throwing cert errors on every site I visit. The only way they can MITM me is if they compromise my PC as well and install their root CA.
- toyg 11y ago... or rather get an intermediate certificate from one of the umpteen root CAs your operating system embeds by default. Is VeriSign going to refuse a certificate to AT&T?
- 11y ago
- oliv__ 11y agoWhy do we have to go through this whole SSL certificates thing and can't just have a simple, automatically secure, I-do-nothing-and-my-website-is-secure protocol? Seriously though. If secure is the default from now on, why can't it actually be the default?
- aembleton 11y agoBecause you need to create a public key for the browser to use.
- rwmj 11y agoSSH gets this right -- create a host key when the server is installed, and have the client check the key and only warn/error when it changes. Sure, this isn't super-secure for first time visitors to their banking website or whatever, but those websites can continue to use the current system.
- nothrabannosir 11y agoSSH doesn't get this right. It's no better than a (auto-pinned) self-signed cert, in our world. I challenge everyone to find in their extended group of friends and colleagues, and their friends and colleagues, a single person who consistently checks the fingerprint* on every first SSH connection. Id personally have a hard time finding someone who even knows it matters. And if you don't? Mitm can get your password, or tunnel your key to another host, bar some crazy ~/.ssh/config which nobody has. WiFi's WPA2 actually does this better than SSH; the passphrase authenticates both parties to eachother, not just one way. I can't set up a hotspot with your home SSID and intercept your PSK---even on initial connection. SSH: nice in a cryptographic utopia, not better than self signed SSL certs when applied to human beings. SSH is just not suitable for humans. Apparently. * a significant part of it, not just the security-through-obscurity random 2 letters in the middle and the last four.
- ryanlol 11y ago-o VisualHostKey=yes
- gesman 11y agoGoogle should offer stupid SSL certificates either for free or for $1/yr. Perhaps at least to customers of Google domains. I won't mind switching from namecheap to Google domain in latter case.
- mikecb 11y agoThey are a platinum sponsor of Letsencrypt, so...done?
- yeukhon 11y agoThat doesn't mean anything other than "we like the idea, you convinced us, we have some budget, we will sponsor in some way money and human resource."
- ultramancool 11y agoIt also means they quite literally at least assist with offering free SSL certificates.
- ryanlol 11y agoEr, isn't that how it'd work internally too?
- mikecb 11y agoIf you're interested in more direct support, please star my ticket[1], it's likely that the same functionality would work for the https loadbalancer as well. [1] https://code.google.com/p/googleappengine/issues/detail?id=12535 https://code.google.com/p/googleappengine/issues/detail?id=1...
- cyphar 11y agoIt means they are supporting a project that provides free SSL certificates. Which more than solves great-grandparent's quip.
- Dylan16807 11y agoMoney and human resource are what make up a company. They give that, and they put their name behind it in support. What else could they do?
- SFjulie1 11y agoYes, shame all libraries/swimming pools giving their schedule online without HTTPS. Shame gutenberg project, the documentations for OS, code, your washing machine. Why would money from libraries gutenberg project, NGOs informations go to more expansive OPEX for web hosting when an information is clearly designed and OK to be public? And does not require adds or payment. Google has some godwin point very authoritative views on the internet and the protocols that make me dislike them. Especially that their business model it is to not pay transit for distributing their contents. Basically every fucking internet users pay the 95th percentile transit to google products even if they don't watch videos on youtube, don't use gmail or else. These people are like ... catholic priests. Do as I say, not as I act and be good members of the community.
- geofft 11y agoWhat additional money is needed to implement HTTPS? It's like an afternoon of a sysadmin's time; it doesn't require any more opex. If you have a favorite library or NGO that doesn't support HTTPS for lack of funding, I am personally happy to donate an afternoon's of a sysadmin's wages to them. (Or to set it up for them, honestly.) Project Gutenberg is already over HTTPS, so I'm not sure what you mean by that. If you think they were strongarmed by Google into it, instead of having decided this long ago as a simple and obvious step for the good of their mission, a reference for that would help inform the discussion.
- schoen 11y agoLibraries in particular can get help from the Library Freedom Project to set up HTTPS. Some librarians have come to appreciate its importance in protecting information about what library resources (like books) patrons are interested in, for library web sites that allow people to do catalogue searches online, for example. https://libraryfreedomproject.org/ourwork/digitalprivacypledge/ https://libraryfreedomproject.org/ourwork/digitalprivacypled... (It's true that that's not the original poster's exact example, which hypothesized a static site that just tells you the library's schedule. But I think library catalogues are a super-great example where information is completely public -- it's not secret what the library has in its collection -- but information about users' interest in that information is private and sensitive, and the people providing the information strongly agree with that concern when they stop to think about it; librarians care very much about not revealing who is interested in which books.)
- drawkbox 11y agoHopefully costs for certificates will come down to encourage it as well. Services like letsencrypt can help.
- conanbatt 11y agoSupply and demand would dictate otherwise
- freehunter 11y agoWell it's not like certs are a limited quantity; they take no time to produce, no limited resources to produce, and no manpower to produce. Supply and demand works when demand outstrips supply, so the price goes up to put downward pressure on the demand. There's no possible way for demand to outstrip supply of certificates, so prices shouldn't go up.
- savanaly 11y agoAs another pointed out, the supply curve for these certs is probably close to horizontal so we should expect the equilibrium quantity to increase but not the price.
- bjblazkowicz 11y agoSo what about the overhead of https?
- geofft 11y agoFor the last few years, effectively zero. https://istlsfastyet.com/ https://istlsfastyet.com/ https://www.maxcdn.com/blog/ssl-performance-myth/ https://www.maxcdn.com/blog/ssl-performance-myth/ https://www.imperialviolet.org/2010/06/25/overclocking-ssl.html https://www.imperialviolet.org/2010/06/25/overclocking-ssl.h... Not to mention that if you use CloudFlare just to get a free SSL certificate out of them, you're also getting a CDN, so the performance overhead is negative.
- drdaeman 11y agoI thought the same, but reality isn't that nice. Got this response: https://news.ycombinator.com/item?id=10602621 https://news.ycombinator.com/item?id=10602621 I was able to replicate this on my own server too, but haven't immediate solution (all the obvious things like OCSP stapling were already configured, following common sense and various "best practices" guides) and I hadn't enough spare time to properly investigate why TLS takes longer. If someone had encountered this or knows the possible culprits, would be glad to hear suggestions.
- geofft 11y agoI don't currently see a 500 ms difference, so maybe they figured something out. From my shell, I see about 35 ms to http://www.stavros.io/404 http://www.stavros.io/404 and about 85 ms to https://www.stavros.io/404 https://www.stavros.io/404 (the HTTPS site serves actual content and the HTTP a redirect, which confounds the numbers). The HTTPS server is currently offering me a 4096-bit-RSA certificate, signed by the 2048-bit-RSA StartCom class 1 intermediate CA. There's no security benefit in a 4096-bit cert signed by a 2048-bit one, since any attacker capable of breaking 2048-bit RSA but not 4096-bit is just going to attack the CA cert and sign their own forged cert (and any attacker sorta capable of breaking 2048-bit RSA will dedicate their brute force effort to CA certs). And to my knowledge, all current CA intermediate certs are 2048-bit. Meanwhile, because of math, 4096-bit certs take a lot longer to handshake: see e.g. https://certsimple.com/blog/measuring-ssl-rsa-keys https://certsimple.com/blog/measuring-ssl-rsa-keys CertSimple's data indicates a 25 ms difference between 2048-bit and 4096-bit keys on their server, so I'd expect that the 4096-bit key is responsible for at least most of the performance difference here. A few years ago I screwed this up on a production shared web host, and I believe we saw a greater than 50 ms difference. (While we're at it, that cert is SHA-1, so it's possible they can get a reissue for free.) Were you able to replicate the 500 ms (!) performance difference on your own server? Are you using a 2048-bit cert and reasonable cipher suites?
- civilian 11y agoIt's funny that vice themselves doesn't automatically forward to https.
- pjc50 11y agoSo is there a lets encrypt solution for shared-hosting systems?
- pfg 11y agoThe solution for shared hosting environments is for your provider to integrate with Let's Encrypt (or any other free CA that might pop up in the future). Once this change goes through, providers will be forced to either do that or (if they think forcing users to keep paying for SSL, even though it's de-facto mandatory) watch their customers move somewhere else. There's plenty of competition out there, and a lot of them already support Let's Encrypt[1]. [1]: https://github.com/letsencrypt/letsencrypt/wiki/Web-Hosting-Supporting-LE https://github.com/letsencrypt/letsencrypt/wiki/Web-Hosting-...
- geofft 11y agoIt looks like `letsencrypt-auto --webroot` does this: https://letsencrypt.org/howitworks/ https://letsencrypt.org/howitworks/ If your shared host has a way to automate deployment of new SSL certificates, this should be easy. (Or if they're willing to manually configure a new cert every 3 months.)
- mikecb 11y agoDomain validation is coming, which makes things easier, but some like Dreamhost are adding one click support to their hosting panels, and openly talk about making it default.
- drivingmenuts 11y agoAll of this raises the question: why does the new default state require action, while the non-default state requires none? Is that more or less bass-ackwards?
- darkhorn 11y agoSeveral weeks ago I have installed certificate to my web site on NGINX and it wasn't hard. It was fun to do. Also I got A+ from Qualys SSL Labs. What I mean is it is easy to deploy an HTTPS site.
- plasticxme 11y agoDeploying TLS in simple environments isn't overly complicated. It's just cost prohibitive.
- donohoe 11y agoWhich is hilarious because the reason I can't switch The New Yorker website to HTTPS is because of ads - which I'm getting from Google DFP which allows non-secure ad assets. In short; Google will penalize me because I use Google. The universe has a sense of humor.
- newjersey 11y agoThey're trying to nudge their customers for a while. It is just a little difficult when that's one's biggest source of income. For example, https://support.google.com/dfp_sb/answer/4515432?hl=en https://support.google.com/dfp_sb/answer/4515432?hl=en
- tyingq 11y agoAlso funny, because for many sites that run DFP or Adsense...that's their biggest source of income. So, G is rationalizing their slow pace with the same reason that's not good enough for others :)
- cryptoz 11y agoSimilarly, Google claimed they would start penalizing websites that showed full-page ads for mobile apps instead of showing you the website. But every single time I try to get to Gmail, or Drive, or Calendar, or any Google service on the web using a mobile device, I'm shown a full page ad for a mobile app. Google has been doing this for years, and it seems like it's also been a year since they said they'd punish all sites that do that. But Gmail still turns up as #1 in search results for email, so does calendar, etc. It seems to me that they have whitelisted themselves and choose not to punish any Google property that breaks the Google rules, despite claiming to do so. Edit: Typically, when a service tells me "no you can't use this service until you view a full page ad" I just give up and not bother continuing to the service. But the same is not true for Google. I reluctantly click through the full page ad every single time. It's incredibly annoying that I let them get away with this and still use the services. They are so outrageously arrogant about it and it bothers me greatly, but still, I don't change. Edit 2: Going to calendar.google.com: http://i.imgur.com/fNRhhYx.png http://i.imgur.com/fNRhhYx.png First results for searching 'calendar': http://i.imgur.com/l3A5Wlh.png http://i.imgur.com/l3A5Wlh.png
- ksk 11y agoI wonder if this will reduce malware that injects advertising into users' browser sessions. Seems like a win-win, but I don't trust Google at all. They want all private data un-encrypted and available for their own analysis/mining/auction when it comes to their own servers and services.
- artichokeheart 11y agoI think one of the big problems with unencrypted websites is shared hosting, who refuse to use SNI certificates (often because it would require upgrading their infrastructure). So users have to pay for a static IP which effectively doubles their hosting costs so most don't bother.
- threesixandnine 11y agoIf they don't bother why should people bother to pay for their hosting? There are many, many hosting companies that do bother and I am using one of them. Had no problem installing Let's Encrypt cert on shared hosting via cPanel there.
- crisnoble 11y agoWho are you using?
- threesixandnine 11y agoI am using ASO.
- wbillingsley 11y agoSurely it could be a lot easier... Everyone already has a known public third party authority -- their domain registrar. Surely the browsers could come up with some protocol where you generate your own keypair, register the public key with the registrar and keep the private key on the server. Then it could work pretty much like SSH, but with the browser doing out-of-band public key checking. Rather than needing a certificate chain, the browser just checks the server's public key matches the published one. If ok, happy to encrypt. If not, wave flags, and yell "spoof". Verifying the registrar isn't a fly-by-night can be as complicated as needs be, but that way the registrar (who already gets paid to register the domain) does the complex hassle, while the ordinary domain-buyer just has to keep their server's public key up-to-date with the registrar (ie, fill in one web form at the time you register the domain or whenever you change the server key). But alas it is not so at the moment. Instead, the current process puts hassle onto millions of individual domain-owners, while keeping life easy for the few (paid) certifying authorities. And then we wonder why so few people want to do it.
- kuschku 11y agoEven better. Put the public key in DNS, auth the DNS.
- colanderman 11y agoThis exists: https://en.wikipedia.org/wiki/Domain_Name_System_Security_Extensions https://en.wikipedia.org/wiki/Domain_Name_System_Security_Ex... It gets some pushback from notable security experts (e.g. tptacek here) because the DNS system (notably the root) is largely state-owned, while registrars are largely privatized.
- wbillingsley 11y agoI thought about that, but there's so many DNS caches out there with potential bugs to make them insecure and poisonable. But a set of public keys from the registrar is "content". It's small, so they could just have a server or two to handle it. (But if load/latency was an issue, well everyone's pretty good at content-distribution networks these days...)
- cballard 11y agoIs there a good guide on making S3 sites work with SSL?
- tshtf 11y agoPretty easy. Use CloudFront instead, which has full SSL support, to serve up the content stored on S3.
- adambrenecki 11y agoYou can use the new AWS Certificate Manager[0] with CloudFront[1], which you can attach to your S3 bucket. The docs aren't brilliant, though. [0]: https://aws.amazon.com/blogs/aws/new-aws-certificate-manager-deploy-ssltls-based-apps-on-aws/ https://aws.amazon.com/blogs/aws/new-aws-certificate-manager... [1]: http://docs.aws.amazon.com/acm/latest/userguide/gs.html http://docs.aws.amazon.com/acm/latest/userguide/gs.html
- mderazon 11y agoIt's very surprising that Google doesn't sell certificates on Google Domains or offer any ssl support in GCE storage stack and yet they are going so strong after web encryption. What about setting an example ?
- mholt 11y agoIn the hopes that it will help spread adoption of HTTPS, I wrote a web server that serves your sites over HTTPS by default, using Let's Encrypt: https://caddyserver.com https://caddyserver.com - It also redirects HTTP -> HTTPS.[1] There's a lot of misinformation out there about certificates and HTTPS, but don't let it stop you from encrypting your site. Regardless of Google's move, there is no excuse for any site not to be served encrypted anymore. [1] Here's a 30s demo: https://www.youtube.com/watch?v=nk4EWHvvZtI https://www.youtube.com/watch?v=nk4EWHvvZtI
- EGreg 11y agoHere's a good excuse for not using https for everything: it breaks caching of files by proxies!
- betenoire 11y agoRight. So what's the solution? I run my wife's retail website. Am I supposed to just stop worrying about caching static assets like product images, scripts, etc.? Do I just throw my hands in the air and assume it evens out because I switched to HTTPS? Serious question, what are my options?
- jacobr1 11y ago* Ensure your server is setting ETags correctly so the clients can determine which assets they need to re-request. * Make use of edge CDNs with https termination
- betenoire 11y agoTurns out my CDN supports HTTPS (using cloudinary), so that's good. Thanks for the ETag reminder, I'm not doing that yet.
- geofft 11y agoDo you run the cache / contract with someone to run the cache, or are you worried about third parties who run caching servers out of your control (like mobile ISPs, corporate networks, etc.)? If the latter, I'm surprised/curious what the use case is. If the former, you can stick those on HTTPS too just fine. CloudFlare will be an entire SSL-enabled CDN for you for free. Amazon Cloudfront will serve SSL for you for free (though you still have to pay for Cloudfront itself, and get a cert on your own, though you can do that for free).
- Mz 11y agoSo, can someone tell me: Will they be assholes and shame BlogSpot sites (i.e. Google's own service)? Or will it be upgraded or something?
- siquick 11y agoI used Cloudflare's free SSL - is this enough? https://www.soundshelter.net https://www.soundshelter.net
- afarrell 11y agoThere are occasionally times when I want to suffer a MITM attack. For example, when I am on an airplane, at a hotel, or basically any other time I have to fill out a webform to get online. Perhaps those forms should not exist, but until they don't, I hope http://xkcd.com http://xkcd.com continues to work.
- schoen 11y agoGoogle has a service for this: https://www.chromium.org/chromium-os/chromiumos-design-docs/network-portal-detection https://www.chromium.org/chromium-os/chromiumos-design-docs/...
- nandhp 11y agoTo clarify, you don't want to suffer an MITM attack; that's just the current standard way of finding the captive portal login page. I believe the Wi-Fi Alliance is working on Hotspot 2.0 (Passpoint) to fix this problem: http://www.theruckusroom.net/2014/10/hotspots-get-hotter-with-release-2-of-hotspot-20.html http://www.theruckusroom.net/2014/10/hotspots-get-hotter-wit... Briefly, it looks like there's a secure (WPA2) hotspot for internet access and an associated open hotspot if you need to sign up for an account (with a published signup URL).
- ninjakeyboard 11y agoShould static content be encrypted over https? I think it's fair for chrome to call out with an x as I've literally seen local lunch joints take orders with credit card info over http but to serve mostly static pages like the new yorker over http only means that the user's privacy is compromised in that people can see what you're reading - does that warrant down ranking searches? I'm just curious - I work mostly on platforms so I'm not too aware of all of the incentives for trying to move everyone to https as it's not my problem domain necessarily.
- eknkc 11y agoOne issue is content injection. You never know what transparent proxies are between you and the server, any one of them can add / remove content, scripts, tracking stuff etc to the static pages. You can't even be sure if your current DNS server resolved to the actual server and not some shady proxy. I believe Comcast has been accused of doing something shady like that but I don't live in US and have no idea. Just read the news.
- Spooky23 11y agoBecause mobile carriers are given broad discretion to do whatever they want to do to your traffic. They cheerfully modify content, and have built infrastructure to do it even more.
- ninjakeyboard 11y agohmm ya this is a good point.
- callmeed 11y agoConsider this: - Squarespace doesn't support SSL (other than on their ecommerce checkout pages) [1] - Weebly only allows it on their $25/mo business plan [2] - Wordpress.com doesn't support SSL for sites with custom domains [3] - If you've never experienced the process of requesting, purchasing, and then installing an SSL certificate using a hosting control panel like Plesk or cPanel, let me tell you–it's a nightmare. All that to say, this is an interesting development that will leave a large % of small business websites with a red mark in their browser. [1] https://support.squarespace.com/hc/en-us/articles/205815898-Does-Squarespace-support-SSL-access- https://support.squarespace.com/hc/en-us/articles/205815898-... [2] http://www.weebly.com/pricing http://www.weebly.com/pricing [3] https://en.forums.wordpress.com/topic/support-for-https-for-custom-domain https://en.forums.wordpress.com/topic/support-for-https-for-...
- cpeterso 11y agoDreamHost now supports Let's Encrypt through their admin panel. The only instructions, however, are a community-maintained wiki page that is already outdated, referring to panel menus that no longer exist. I successfully obtained my certificate, but it was not easy.
- tobtoh 11y agoBased on your comment, I went over to see if I could obtain a certificate. It took all of 5 seconds for me to do - it's all automated via the admin panel now. Just tick the box to make your site secure. Looks like DH has resolved any initial issues they had.
- BinaryIdiot 11y agoYeah I'm all for SSL shaming but my personal site with SquareSpace is about to look like shit for me since I'm a web developer. I mean as a web developer it's not going to look good if your portfolio is shown with a security warning. I wonder if SquareSpace is going to finally fix their shit or if I'm going to have to move elsewhere which is going to be a pain (I went with SquareSpace because I didn't want to be assed with dealing with much of anything for a personal site).
- dh997 11y agoHN could do its part: for example, start marking all http:// http:// links red. For our content sites, we can also announce to users this change and roll something out.
- Nutmog 11y ago"mark non-secure origins as non-secure." The name of that option seems to be chosen to apply a bit of pressure to anyone who sees it. Nothing wrong with that of course - it's our existing habits of trusting HTTP that are strange.
- 5ilv3r 11y agoThis is stupid. Making https a requirement will break most web pages on hardware older than 2005 or so. This sucks for anyone without money.
- Throwaway23412 11y agoAre there hardware requirements for encryption? And, if there are, who are these people building web sites on hardware older than 2005?
- icebraining 11y agoIt doesn't make HTTPS a requirement; it just shows a red lock.
- drummer32 11y agoYes let's cripple the web by continuing to use unencrypted http, just because computers from 15 years ago won't be able to properly display some webpages...
- dh997 11y agoBasically efficient, low-latency caching for html and css content is over unless there's SRI for them. It makes sense to have a mini webpage delivered securely that lists hashes for all static assets, and then serve some static assets insecurely to take advantage of CDNs as long as they don't disclose individual app actions (assets everyone sees on many pages). The downside is the balancing of risk for activity leakage based on insecure assets. Of course, some dynamic content and sensitive state needs to remain secure. The issue is that securing everything depends on whether you're willing to trust your CDNs and caches with your certs and private keys (granted, you already trust them to display the correct content.). That sort of technical risk management needs to be considered carefully if insecure assets can dramatically speed up UX (because TLS sessions take some or a lot more work... since how would the browser and backends do session caching or pipelining across infrastructures and providers that likely have multiple IPs? One connection per provider, each keeping their own cache for their HA boxes?) Maybe there needs to be an insecure HEAD or CACHE open standard to check content freshness of a secure page via crypto hash (say canonical uri, etag and last modified) to avoid building up a full TLS session to see nothing's changed?
- sqldba 11y agoIf they could just wait until cPanel has LetsEncrypt support that would be great...
- eccstartup 11y agoIt's like developed countries shame developing countries.
- coder-otherstuf 11y agoWhile I am a fan of HTTPS everywhere, there are just some use cases that are not feasible for HTTPS. One edge case I am familiar with is a case where a webapp is used to setup a headless device (like a wireless repeater or hub for example). In this scenario, a user loads the page from a web server, the page instructs the user to put the device in a mode that it acts as a WiFi access point, the user then changes the access point of their machine, the page can now make AJAX requests to the device access point which is also acting as a server allowing the user to POST things like WiFi credentials for the device to use. In this edge case one of two things need to happen, either the original page must be served as HTTP since no CA will issue you a cert that can be served by such a device. Or the device must act as more than a simple API server and would have to serve HTML pages which would get linked to by the original page. While the second solution is fine to get HTTPS everywhere (with the exception of while connected to the device), it means that the development and improvement of setup UI is tied to device firmware updates as opposed to speed and flexibility of web development.
- ssalat 11y agohttps://news.ycombinator.com/item?id=5238164 https://news.ycombinator.com/item?id=5238164 Still not solved... calm down Google!
- finnn 11y agoUse Let's Encrypt to automatically issue a cert valid for each domain?
- jrbapna 11y agoHow will this impact page-speed? I recall switching the product pages of an e-comm site, which had up to 50 small images per page, from https to http and the change very significantly increased page load speed for the end user
- srj 11y agoI'll guess that the browser opened several connections to fetch all of the content (to work around broken http/1.1 pipelining) and needed to complete many tls handshakes. http2 probably would have done a better job.
- tobltobs 11y agoAnd I always thought TLS is the virtual equivalent to those TSA locks.
- chipperyman573 11y agoWhat gave you this impression?
- tobltobs 11y agoThe uncontrollable number of masterkeys.
- bphogan 11y agoWhy don't I like this? I don't think it's HTTPS.... I think I don't like that one company has this much power over the web. This seems awfully familiar...
- sdrothrock 11y agoI don't like this because I've always thought that HTTPS shouldn't be a mandatory baseline. It doesn't make a whole lot of sense to me that a random website with no financial transactions or anything should require HTTPS. [Edit: And thus, it makes less sense to me that the site should be penalized by anyone for NOT having it.] "Ah, yes. Bob's Trivia Emporium has HTTPS. I know this is really Bob's site and that the data is from his site." If anyone has compelling arguments to the contrary, I'm open to hearing them.
- frankchn 11y agoHTTPS assures the integrity of the data transferred is from the origin domain, so it prevents your ISP from injecting additional ads into tour site, which some ISPs like to do [1]. [1]: http://arstechnica.com/tech-policy/2014/09/why-comcasts-javascript-ad-injections-threaten-security-net-neutrality/ http://arstechnica.com/tech-policy/2014/09/why-comcasts-java...
- sdrothrock 11y agoThat doesn't convince me; it's like saying every Tom, Dick, and Harry should get encrypted phones because Verizon has the capability to tap into conversations. The onus should be on the provider, not the customer.
- nickik 11y agoYou dont think that normal user should use encrypted phone sevices? Are you serious?
- srj 11y agoSuppose you go to Bob's trivia emporium in your browser and a MITM inserts malicious javascript content into the response. Looked at another way: Is there any reason http should not be secured with some sort of privacy and integrity check?
- xdinomode 11y agoMy website runs on a vps with NodeJS as the backend. I could easily self sign a certificate but chrome displays a huge warning to users. How about signing certificates for free google. Https is easy to implement but the fact that it costs is bs.
- chipperyman573 11y agoLetsEncrypt offers free, automated certificates and is recognised in all major browsers (IE, Chrome, FF, Safari). https://letsencrypt.org/ https://letsencrypt.org/
- xdinomode 11y agoOh wow I've actually heard of this before thanks for the tip.
- shurcooL 11y agoSounds good to me, thanks to Let's Encrypt. All my personal sites are now on https and HTTP/2 (thanks to Go 1.6). I don't use ads so I have nothing blocking me from https. The only situation where I still want to use HTTP is one page I serve, which uses websockets, and I don't want to use secure websockets, but that's the only exception. I'm glad to be in this boat. Once again, it's mostly thanks to Let's Encrypt being awesome, and I'm thankful to it.
- protomyth 11y agoIs there a checklist somewhere that specifies each of the things that Google requires / forbids?
- akorchemniy 11y agoThis might have the unintended consequence of causing people to go numb to the "false positive"
- userbinator 11y agoThe article title really, really needs an extra word: "Chrome", between "Google" and "Will". At first glance I thought it would be about the search engine, which would be a very disturbing thought indeed; it's already hard enough to find the older, highly informative and friendly sites --- which often are plain HTTP. Nevertheless, quite convincing security arguments aside, I feel this also has a very authoritarian side to it: they are effectively saying that your site, if it is not given a "stamp of approval" by having a certificate signed by some central group of authorities, is worthless. Since CAs also have the power to revoke certificates, enforced HTTPS makes it easier to censor, control, and manipulate what content on the Web users can access, which I certainly am highly opposed to. I can see the use-case for site like banks' and other institutions which are already centralised, but I don't think such control over the Web in general should be given to these certificate authorities. With plain HTTP, content can be MITM'd and there won't be much privacy, but it seems to me that getting a CA to revoke a certificate is much easier than trying to block a site (or sites) by other means, and once HTTPS is enforced strongly by browsers, would be a very effective means of censorship. Thus I find it ironic that the article mentions "repressive government" and "censor information" --- HTTPS conceivably gives more power to the former to do the latter, and this is very much not the "open web" but the centralised, closed web that needs approval from authorities for people to publish their content in. There's a clear freedom/security tradeoff here, and given what CAs and other institutions in a position of trust have done in the past with their power, I'm not so convinced the security is worth giving up that freedom after all...
- nitrogen 11y agoWhat we really need is opportunistic unauthenticated encryption with key pinning as a fallback between CA-signed https and plain http. Beating mass passive snooping is worthwhile even if MITM is still a risk.
- lambau 11y agoI agree! There is TCPCrypt, for example: http://www.tcpcrypt.org/ http://www.tcpcrypt.org/
- 11y ago
- BogusIKnow 11y agoMain problem still is Google: They consider HTTPS and HTTP links the same. When switching a site to HTTPS you lose all your incoming links. Redirects only transfer a small amount of juice. You're toast. We tried migrating several times to HTTPS only, every time got a huge penalty from Google. So Google is the main driver for HTTP websites.
- gabemart 11y ago> They consider HTTPS and HTTP links the same. When switching a site to HTTPS you lose all your incoming links. Do you mean that they don't consider HTTPS and HTTP the same? Otherwise, I don't understand your point here.
- BogusIKnow 11y agoYou're right.
- frik 11y agoHTTP + HTTPS is fine HTTPS for SaaS and e-commerce web apps is fine HTTP for normal websites is okay (for me, I have no hidden agenda) HTTPS-only for normal websites is silly, why not offer HTTP too? Every request is unique, no internet anonymity.
- jve 11y agoHTTP for normal websites may allow your website visitors to participate in DDoS: https://blog.cloudflare.com/an-introduction-to-javascript-based-ddos/ https://blog.cloudflare.com/an-introduction-to-javascript-ba... Happened to GitHub once.
- agildehaus 11y agoWhy is HTTPS-only for normal websites silly? It ensures the page was not tampered with enroute.
- frik 11y agoWhy not HTTP + HTTPS? Let the user decide. HTTPS-only is silly for normal websites. Visitors from cooperate networks or some countries would say, your second sentense doesn't hold in the real world.
- deleted 11y ago[deleted]
- tobbyb 11y agoI feel a bit of dissonance on hn on the issue of https. On issues of surveillance and spying the responses are often measured and there is generally a balanced debate, and yet on ssl suddenly its a matter of extreme urgency with strident positions backed up by references to mitm, spying and isp injected ads. This is not as urgent a matter as some here tend to make it, better to resolve it properly than rush into half baked solutions like Google shaming websites. Why should a private company have the ability to shame websites and drive decisions a certain direction without any consultative process and accountability. Surely these are decisions for industry groups and wide consensus, and not individual corporates driven by self interest. Corporates routinely mitm ssl traffic and no one is shaming them or the equipment makers for that, so ssl and mitm is hardly going to be problem for state actors. For protection against less influential actors, banks and those who process sensitive data have been on https for a long time now so where is this urgency and the need to take action coming from? Everyone agrees security is good but the mechanism to enable this cannot be given up to browser makers and CAs. This is a complete loss of end user control and a significant step back from the open net that cannot just be brushed aside. Not everyone needs https and for ads injections the pressure should be on ISPs to stop the illegal behavior. Why can't we shame ISPs instead of forcing all websites to https? Other solutions like signing content that empowers individuals rather than corporates and vested interests should be explored. The same browser makers went ahead and arbitrarily started flashing grave warnings on self signed certs without any consultative process or accountability.
- CM30 11y agoSo what would this mean for web development agencies and the likes, who've made hundreds of thousands of websites (most without SSL) and would now be forced to convert them all to use https? How many clients would be willing to pay to cover some of the time wasted doing that? And how about the potential SEO impact? I mean, Google says switching to https shouldn't affect things, but I've seen tons of sites lose rankings after a change. Okay, using https is a good thing and all, but the inconvenience caused by having to make this change could be massive.