12 ms·
WordPress.com turns on HTTPS encryption for all websites
- ikeboy 10y agoGreat. Tumblr enabled it earlier this year as well.
- geostyx 10y agoAwesome to see stuff like this. LetsEncrypt is really doing a great service to make the Internet a better place.
- pfg 10y agoOriginal announcement: https://en.blog.wordpress.com/2016/04/08/https-everywhere-encryption-for-all-wordpress-com-sites/ https://en.blog.wordpress.com/2016/04/08/https-everywhere-en...
- dankohn1 10y agoKudos to the Let's Encrypt and Wordpress teams. This is what the future looks like. Every webpage needs to be encrypted, and http (as opposed to https) needs to go the way of telnet (as compared to ssh). What's particularly great is that there is no configuration of any kind for Wordpress authors or their readers. Like they have done, we need to always default to secure.
- geostyx 10y agoI still see login pages over http sometimes. I will be happy when I rarely see any http pages. I wonder what would happen if Chrome made all http pages red to indicate insecure...
- Sidnicious 10y agoThey plan to: https://www.chromium.org/Home/chromium-security/marking-http-as-non-secure https://www.chromium.org/Home/chromium-security/marking-http...
- colinbartlett 10y agoThere's a Chrome flag you can enable for that experience today, as it's only a matter of time before that is default. I use this and so this is how the TechCrunch article shows for me: http://i.imgur.com/c8Cz7S4.png http://i.imgur.com/c8Cz7S4.png
- pointytrees 10y agoAnd, that imgur link is also a broken lock? ;)
- inglor 10y agoJust the fact http was the default for all websites hosted on WordPress.com is really weird to me. All those websites had all the passwords sent over plaintext.
- pfg 10y agoNote that this is about custom domains hosted on Wordpress.com's infrastructure. Blogs that were hosted as subdomains of wordpress.com have been using SSL since 2014 according to the original announcement. Let's Encrypt allowed them to enable it for custom domains without delivering a truckload of money to a CA. The original announcement is a bit more precise on this.
- pmaiorana 10y ago
- kyledrake 10y agoNot to say this is a bad thing, but I'm sure Wordpress just broke a lot of links on their user's sites. For example, any embedded images from other servers not using HTTPS means that they won't load anymore due to browser policies, essentially breaking the links. It also means that any embedded images/videos/etc. will only work if the remote server has HTTPS. Again, not a bad thing, but it's pretty painful to have to deal with this with a lot of users that aren't experts on HTTP, and I'm sure it's a similar story at Wordpress. I can flip the switch for default HTTPS on Neocities in a day. The hard part is figuring out how to not break user's sites in that process. Ideas welcome.
- deleted 10y ago[deleted]
- deleted 10y ago[deleted]
- skeltoac 10y agoWe've been working on this for quite a while and several parts of the solution deal with rewriting embedded URLs using HTTP. If you have any examples of breakage, let us know.
- toomuchtodo 10y agoAny plans to use HSTS and preloads header to default to SSL in browsers for Wordpress-hosted sites?
- barsxl 10y agoYes, we're working on it.
- CharlesW 10y ago> If you have any examples of breakage, let us know. I believe it's breaking podcast feeds being served with WordPress.com, because iTunes doesn't support Let's Encrypt certificates. https://www.dominicrodger.com/2016/02/29/lets-encrypt-itunes-podcasts/ https://www.dominicrodger.com/2016/02/29/lets-encrypt-itunes... This may not affect a lot of customers (since WordPress.com doesn't support PowerPress for feed generation), but I know some podcasters create feeds by hand or with other apps. This issue will cause at least some podcasts to disappear from iTunes without warning unless you can coordinate with Apple to fix it.
- chinathrow 10y agoNice. However, they could have shelved out a couply of hundred of bucks for a wildcard cert before.
- cavisne 10y agoThis includes custom domains not just *.wordpress.com
- chinathrow 10y agoThanks, that was the missing thing!
- derf_ 10y agoIs it not live yet? The article uses the present progressive "is activating", but e.g., https://whatever.scalzi.com https://whatever.scalzi.com serves a certificate whose CN is *.wordpress.com (i.e., one that is invalid for the intended domain).
- pmaiorana 10y agowhatever.scalzi.com is on WordPress.com VIP—same platform, but a different segment of users. Our VIP sites often use 3rd parties (mostly ad servers) that don't yet support https, so we haven't defaulted any of those sites to https—it's an option available if they want it though!
- deleted 10y ago[deleted]
- teekert 10y agoLet's encrypt is great, but I'm still running into people that have Chrome on WinXP or even IE8. It's crazy, I know. They did promise to start supporting both o XP because it had something to do with an intermediate cert somewhere. They didn't deliver on that promise. I don't blame them. By the way, the cert on Wordpress.com is issued by GoDaddy, all the examples I could come up with are also. Guess it's a roll out process.
- ran290 10y agoThey did: https://community.letsencrypt.org/t/upcoming-intermediate-changes/13106 https://community.letsencrypt.org/t/upcoming-intermediate-ch...
- joshmoz 10y agoWindows XP support was rolled out March 25 2016. You can find more information about upcoming and completed features here: https://letsencrypt.org/upcoming-features/ https://letsencrypt.org/upcoming-features/
- haroldp 10y agoBut that doesn't really help you if you are using SNI to host multiple sites on a single IP address, does it?
- pfg 10y agoInternet Explorer doesn't support SNI on Windows XP, correct. Let's Encrypt doesn't force you to use SNI, though. SNI is not something you "stick" on a certificate - it's a TLS extension which you don't have to use at all.
- rjbwork 10y agoIt also, ironically, broke a bunch IIS and Azure Web App hosted sites due to an incorrect intermediate being sent by the servers, with no recourse for new and renewing users at the moment...See https://github.com/sjkp/letsencrypt-siteextension/issues/42 https://github.com/sjkp/letsencrypt-siteextension/issues/42
- pred_ 10y agoMeanwhile, the chromium preload list just passed 10.000 domains. Things are moving forwards. https://twitter.com/lgarron/status/718242465782853633 https://twitter.com/lgarron/status/718242465782853633
- Matt3o12_ 10y agoDo you know how they're stored on my PC? Last time I checked they were all in a giant C source file, which sounds like a pretty bad idea to me since I can't imagine it'll scale well.
- muloka 10y agoThis is awesome news. I wonder if Squarespace will follow suit in this endeavor.
- PuffinBlue 10y agoSquarespace already allows this for non-custom domains, but if you have a custom domain then you can't use https. I hope this move by Wordpress will push Squarespace to support https for custom domains as it's a very frequently requested feature.
- rogerbinns 10y agoIs anyone providing a certificate solution for LAN deployed devices/software where there isn't a stable name, or for that matter an administrator? https://news.ycombinator.com/item?id=11457567 https://news.ycombinator.com/item?id=11457567
- simonw 10y agoWordPress.com illustrates an interesting challenge in supporting SSL if you allow people to use subdomains on your service: https://bestcrabrestaurantsinportland.wordpress.com/ https://bestcrabrestaurantsinportland.wordpress.com/ works fine https://www.bestcrabrestaurantsinportland.wordpress.com/ https://www.bestcrabrestaurantsinportland.wordpress.com/ displays a certificate warning Unfortunately I don't think there's a good solution for this. Humans are gonna www- things.
- hayksaakian 10y agocan you get a second certificate? i'm not sure how the technology works, but since let's encrypt is free i think it could also be automated to solve this problem
- dsr_ 10y agoLE allows you to put many names in the same cert. Adding www is extremely simple.
- jquast 10y agoThere is a feature in X.509 for this, "Subject Alternative Names" to cover these alternate hostnames. https://en.wikipedia.org/wiki/SubjectAltName https://en.wikipedia.org/wiki/SubjectAltName http://wiki.cacert.org/FAQ/subjectAltName http://wiki.cacert.org/FAQ/subjectAltName https://www.openssl.org/docs/manmaster/apps/x509v3_config.html https://www.openssl.org/docs/manmaster/apps/x509v3_config.ht... Certificate authorities charge extra for it, of course they do. DigiCert brands this as "Multi-Domain (SAN) Certificate" and charges nearly $300/yr, while my choice provider, sslmate.com offers the same for $25/yr. And now $0 certificates with Let's Encrypt, I'm sad to see sslmate.com's business hurt, as they are the first to provide no-bullshit sysadmin-focused CLI tools to get the job done. I'm very wishful to see DigiCert.com and others like it go bankrupt, however. I don't see any reason why Honest Achmed's request to be a CA was denied by Mozilla, https://bugzilla.mozilla.org/show_bug.cgi?id=647959 https://bugzilla.mozilla.org/show_bug.cgi?id=647959 at least he is honest about his business model.
- pg_is_a_butt 10y ago
- hising 10y agoI think this is awesome news. Hopefully we will see Chrome starting marking http only sites as non-secure and Apples App Transport Security (ATS) forcing people to switch to https all over the web within a year or two. https://www.chromium.org/Home/chromium-security/marking-http-as-non-secure https://www.chromium.org/Home/chromium-security/marking-http... https://developer.apple.com/library/ios/releasenotes/General/WhatsNewIniOS/Articles/iOS9.html#//apple_ref/doc/uid/TP40016198-SW14 https://developer.apple.com/library/ios/releasenotes/General...
- dogweather 10y agoA little on-topic hype if allowed: free "HTTPS Everywhere" monitoring https://nonstop.qa https://nonstop.qa. Hacker News passes with flying colors: https://nonstop.qa/projects/387-hacker-news https://nonstop.qa/projects/387-hacker-news (Free because I'm applying the GitHub model: free public projects, will eventually charge for private ones.)
- wfunction 10y agoNot relevant to the WordPress part, but can someone explain to me why websites like eBay don't run on HTTPS except during login? Doesn't that allow any sniffer to steal your authentication cookies?
- jacobparker 10y agoYes and it doesn't even protect the password appreciably either. User logs in with HTTPS, gets redirected to HTTP site and the MitM throws up the "Incorrect password try again" page. User types their password and transmits it over HTTP or JS steals it etc. etc. eBay does it because they aren't sufficiently interested in protecting against MitMs. The web isn't ready for HTTPS only yet but it will happen over time.
- ultramancool 10y agoIt's already pretty much happened, I can search google, browse wikipedia, read email, HN and reddit, even click the images on imgur all without leaving the SSL comfort zone. Even facebook seems to have taken this route. Most big sites now offer SSL-only.
- ultramancool 10y agoYes, yes it does. It's pretty annoying, aliexpress does similar too. You'd think big ecommerce sites would have caught up with this. As for their reasoning... maybe performance, but more likely laziness.
- at-fates-hands 10y agoFrom their perspective, its not their issue. If a user gets their credentials hijacked, and a hacker makes a bunch of unauthorized purchases with their saved credit card, who's the customer going to call? AliExpress or their bank to mark the purchase and fraudulent and refund the money? To them, they're merely supplying the vehicle to do business. It's the payment processing companies, the banks and third party vendors who handle the money, so its their responsibility to notice the charges and shut the account down. Like last week, I got a call from my bank asking if I was making purchases in Belgium, Norway and France. I was like, "Uhhhhhhhhhhh no, that's fraud." They blocked the purchases first and THEN called to confirm with me. It was pretty obvious based on my banking behavior this was out of the norm and immediately flagged. It wasn't the travel sites fault they let it happen, it would've been my banks problem if they let those purchases go through. I'm glad they have an incredible fraud detection system. This is the second time they've flagged something on my account and shut these down before any damage could be done.
- dredmorbius 10y agoThis is great news. All the more so as there is a tremendous amount of high-quality content under the Wordpress.com domain, something I chanced on while seeking out signs of intelligent life on the Internet. https://www.reddit.com/r/dredmorbius/comments/3hp41w/tracking_the_conversation_fp_global_100_thinkers/ https://www.reddit.com/r/dredmorbius/comments/3hp41w/trackin...
- anarcat 10y agoI wonder how they work around Let's Encrypt rate-limiting?
- pfg 10y agoThis is about custom domains, not subdomains of wordpress.com (they're using a wildcard cert for that, and have been for years). Rate limits aren't much of an issue in that scenario unless someone has more than 20 separate subdomains set up as a WordPress.com blog under the same domain. Even then, you could theoretically get 20 * 100 subdomains covered every week if you're smart about which domains you combine on a single SAN certificate.
- anarcat 10y agoThose are the rate limits, as far as I understand them: * 100 Names/Certificate (how many domain names you can include in a single certificate) * 5 Certificates per Domain per week * 500 Registrations/IP address per 3 hours * 300 Pending Authorizations/Account per week It seems to me that WP.com could reach at least one of those... So I was curious to hear how they were doing that. And yes, I was wondering if they would replace the *.wp.com wildcard - i guess not...
- pfg 10y agoThe rate limits have been changed to 20 certificates per domain per week recently. The registrations/IP rate limits aren't really a problem - WordPress could, in theory, run their entire Let's Encrypt infrastructure using one registration (account). Pending authorizations shouldn't be much of an issue given that all custom domains are CNAMEs pointing to their servers, so they should be able to solve all challenges. (By the way: If you're building a large integration, Let's Encrypt can change the rate limits for you.)
- deleted 10y ago[deleted]
- RawInfoSec 10y agoWhile this helps *.wordpress.com users or custom domains using the wordpress.com back end, it's going to cause a ruckus with self hosted ones. Neither WordPress or LetsEncrypt has any way to modify global server setting on any shared hosting environment. Slapping in an SSL certificate doesn't make a site secure, properly configuring the services that use the cert is what makes it secure. GoDaddy isn't going to let Company Xyz rebuild Apache or configure cyphers server-wide... In the end, while this is a move in the right direction, I fear it will give false confidence to many web providers that don't have enterprise experience with security fundamentals.
- CM30 10y agoThis won't affect self hosted sites, only those on WordPress.com's platform. A lot of the code for that service isn't present in the self hosted script. So it won't break servers or shared hosts.
- barsxl 10y agoMany of the larger webhosts have free (but not mandatory) SSL support in production, beta, or on their near-term roadmap.
- vram22 10y agoGoogle's Blogger is moving to https too, over time, my dashboard shows.
- frugalmail 10y agoWordpress is still a security nightmare. PHP, mostly dyanmic everything, unmoderated cesspool of plugins, themes, etc... where you just drop code, predictable URLs and pages to brute force, I could go on...
- iimpact 10y agoI would recommend the HTTPS everywhere extensions for your fav. browser. It forces all web-pages to be loaded using HTTPS (if available). https://www.eff.org/HTTPS-everywhere https://www.eff.org/HTTPS-everywhere
- micro-ram 10y agoKB SSL Enforcer allows you to automatically build your own enforced HTTPS list. https://chrome.google.com/webstore/detail/kb-ssl-enforcer/flcpelgcagfhfoegekianiofphddckof https://chrome.google.com/webstore/detail/kb-ssl-enforcer/fl...
- pred_ 10y agoIf available, and if someone has added it to the database of more or less manually maintained rulesets for redirection; https://www.eff.org/https-everywhere/atlas/ https://www.eff.org/https-everywhere/atlas/ https://github.com/EFForg/https-everywhere/tree/master/src/chrome/content/rules https://github.com/EFForg/https-everywhere/tree/master/src/c...
- brainpool 10y agoLet's Encrypt is great, but Start SSL has also shaped up considerably. A while back their process and the GUI was a real stumbling point. Today however it is a breeze to get it going. (Disclaimer: I am in no way affiliated with Start SSL)
- nsgi 10y agoAmazing what a bit of competition can do.
- upbeatlinux 10y ago12+ years in the making.
- billhendricksjr 10y agoSquarespace needs to follow suit
- emdd 10y agoDoes SquareSpace do any encryption for non-admin log in things?
- deleted 10y ago[deleted]
- ne01 10y agoI wonder if they bundle multiple domains in one certificate?