5 ms·
"...I care about my own privacy and security..." and yet your website has no encryption. Thus, when I enter my details on your form, it is being passed over the
by phantom_oracle 10y ago
"...I care about my own privacy and security..." and yet your website has no encryption. Thus, when I enter my details on your form, it is being passed over the same internet in plaintext, thereby violating the exact "privacy and security" this "protest" aims to create.
- codemac 10y agoWell, I think the concept here is to publicly pledge to dump yahoo, in order to convince & pressure others to do the same. Saying you care about your privacy and security doesn't mean you remove yourself from all forms of public expression. It's the most basic form of free speech. If you want to privately pledge, just write it down on a sticky note, and put it on your monitor.
- bbcbasic 10y agoStill. I think its a bit absurd.
- CobrastanJorji 10y agoThis is a site collecting information for a public petition. By definition your GOAL is to share your information publicly. How is it absurd to do so in the open?
- bbcbasic 10y agoWhat if I decide I don't want to share publicly. By then the contents of the page as I have viewed have been sent unencrypted.
- johnmaguire2013 10y agoYour headers would still be unencrypted -- including the domain and URL you accessed.
- alexbecker 10y agoThe domain is unencrypted over HTTPS, but the path is encrypted.
- palunon 10y agoSo the difference is "you accessed www.dumpyahoo.com" vs "you accessed www.dumpyahoo.com asking for / "...
- alexbecker 10y agoI agree in this case it isn't very helpful.
- johnmaguire2013 10y agoThanks for the correction.
- eastWestMath 10y agoExactly what do you not wish to share publicly? Signing a petition is public by definition.
- jrs235 10y agoThe form action appears to use https. But yeah, it is 2016 and https should be the norm for even just loading pages with forms.
- angry-hacker 10y agoI host 20 sites from simple vps box with nginx. AFAIK i need an ip per domain to have ssl, unless I use something called sni, but I don't know how to set it up with nginx + let'sencrypt It's not that easy. Of course I could just throw cloudflare in front of everything, but no thank you.
- aparadja 10y agoHmm? I run multiple https sites from a single Linode box without any issues. Nginx + letsencrypt.
- angry-hacker 10y agoSo you are using SNI?
- pixl97 10y agohttps://forums.freebsd.org/threads/57447/ https://forums.freebsd.org/threads/57447/ Shows working sni with nginx and let's encrypt. You've probably done the same config error
- aparadja 10y agoHonestly, I don't even know. I'm not familiar with SNI. All I know is I didn't have to do anything special to get the 2nd domain running ssl on the same box. It just worked right away as expected. I wasn't even aware that there might be complications.
- detaro 10y agoYou don't need to set up anything specifically for SNI, nginx does that out of the box. Unless you have to serve really old clients (some WinXP and android <2.3 I think?) SNI is no problem at all.