3 ms·
Yes, there are many reasons to deploy TLS everywhere, and everyone should be working towards it for these reasons: - Increased resistance to surveillance. Inst
by Titanous 11y ago
Yes, there are many reasons to deploy TLS everywhere, and everyone should be working towards it for these reasons:
- Increased resistance to surveillance. Instead of seeing the pages/information that a client downloads from your server, state actors, ISPs, local attackers, and anyone else listening only learn that the client downloaded some bytes from your server.
- Mitigation of man-in-the-middle and man-on-the-side attacks against your website. These can be as simple as someone attacking a local open Wi-Fi access point to sophisticated attacks like the Chinese DDoS against GitHub and the NSA's QUANTUM INSERT. Potential attacks range from replacing/rewriting information to attacking client machines with browser exploits.
- Better SEO rankings, Google weighs HTTPS sites higher than their equivalent insecure plaintext.
If you need a shared host that supports HTTPS, take a look at DreamHost, they have a free one-click Let's Encrypt integration.
- awqrre 11y agoI pay $5/month for my shared hosting for 100GB disk space and unlimited bandwidth but it doesn't support HTTPS...
- everfree 11y agoSorry to hear that. HTTPS (via SNI and user-uploaded certificate) doesn't cost the hosting provider anything to support, so it seems like yours is just behind the times.