3 ms·
Totally agree, encryption by default is the best option. However: And if SSL is offered perhaps it should still be possible to access non-security-critical
by fbender 10y ago
Totally agree, encryption by default is the best option. However:
And if SSL is offered perhaps it should still be possible to access non-security-critical pages by plain old HTTP.
I often thought about setting up a forwarding proxy for my sites that listens on `un{encrypted,secure}.mydomain.tld` and provides plain old, non-optimized and unencrypted HTTP/1.1 access for those who wish to access the sites that way. I've experienced the issue with slow loading times when roaming (bandwidth is expensive) and/or in remote areas (very low bandwidth and spotty coverage) a couple of times, and having low-profile variants for browsing essential stuff would've helped a lot.
However, I'm not sure if this will open attack vectors for the unencrypted sites. I.e. I'd imagine that a man-in-the-middle-style attack could show the main site / URL (www.mydomain.tld) with another cert and just forward the un{encrypted,secure} content … but then again, this is not a new technique and can be prevented by public key pinning (though, https://news.ycombinator.com/item?id=12434585 https://news.ycombinator.com/item?id=12434585 :-/), DNSSEC/DANE (no browser vendor buy-in yet), etc.
Any idea if this were a sane idea for other sites as well? With enough momentum, browser vendors could detect and display un{encrypted,unsecure}. sub-domains specially.