6 ms·
Still not changing my websites to https. They don't need to be "secure", they are not going to be "secure". I consider this a broken stupid change.
by jbb555 10y ago
Still not changing my websites to https. They don't need to be "secure", they are not going to be "secure".
I consider this a broken stupid change.
- Aaron1011 10y agoWhy? Without HTTPS, anyone between a user and your server can modify your page, without you noticing.
- madeofpalk 10y agoThere are certain types of sites where that doesn't really matter. My personal blog, for instance, I don't see the need for HTTPS there. In saying that, HTTPS is easier than ever to deploy to a website. This will only increase adoption of 'secure by default'
- Symbiote 10y agoPeople modifying your page can include ISPs injecting ads or reducing the resolution of images to save bandwidth.
- userbinator 10y agoI'm not the parent, but I say "let them".
- andybak 10y agoHow about injecting malware?
- Klathmon 10y agoAnd this isn't a "it could happen some day" threat, it's already a thing. There are simple one-click setup programs that can monitor a wifi network, and inject malware into any downloads of executable or zip files that it can find. With things like Stagefright still affecting a scary large amount of android users, what happens when someone starts injecting malware into images which can compromise an entire phone without so much as a hiccup.
- crottypeter 10y agoWhat if they inject hate speech / child porn / <any illegal content> and tell the authorities on you?
- userbinator 10y agoLike I said, "let them". The authorities will see nothing wrong with the content on the server, and look somewhere else. What happens "in transport" is absolutely not my responsibility. It could even serve as a sort of plausible deniability...
- throwaway6845 10y agoWhich has long been my suspicion why Google is so keen on promoting HTTPS. If all sites are HTTPS, Google kills ISPs' ability to inject ads and to profile customers. Not through any sense of altruism, but because Google is only interested in one megacorp being able to sell ads and track browsing: Google. It's good business for Google, but let's not pretend it's about "making the web better". It's about keeping commerce on the web as a Google monoculture.
- swiley 10y ago@symbiote I'm also unwilling to switch to https. If your ISP is attacking you then you should be tunneling things. I personally like the image compression and caching that they do and think it's somewhat important for my site and others like it.
- witty_username 10y agoSomeone could modify a link in your blog to go to malware. Example: "Hi guys, I like software X, download it here"
- xylon 10y agoMe too. Google can do what they want but they don't own the Internet.
- castell 10y agoI am with you. In many use cases HTTP 1 is fine. And as we have seen with the Hearthbleed bug, if you cannot devote resources to keep your HTTPS up-to-date all the time 24x7, it makes your server and the user sessions more insecure. And often providing HTTP and HTTPS makes sense too. So I am against labeling HTTP as "evil" or legacy. We should look who has an interest in doing just that, and why they are forming initiatives. Beside all that pretty much all ad-networks serve HTTP ads, so if you want to loose much of your ad revenue, please go with the HTTPS-only route and face the real world surprise.