3 ms·
Ahh yes... the whole site is on HTTPS. I'm not sure what the best approach is for the SSL. It looks good when people go to the site and see the seal, they know
by stulogy 16y ago
Ahh yes... the whole site is on HTTPS.
I'm not sure what the best approach is for the SSL. It looks good when people go to the site and see the seal, they know its a secure site. But it can slow things down. I could make it so that only the actual logged in interface, and the signup page are secure. What do you think?
- paraschopra 16y agoI don't think you should keep the HTTPS in default. It really slows down the speed of the site, maybe just keep it on payment and login page.
- MichaelApproved 16y agoSSL is very resource intensive. I can understand wanting to show security on the homepage but you should definitely turn it off for the site tour and other pages like TOS.
- qq66 16y agoI run a site entirely on SSL using a Redline 3250. It's literally a 30-minute setup -- the server does not know that it is running a secure site. Listed for $35,000 in 2003 - bought mine on EBay for $200.
- egoz 16y agoThat site even use https to serve images. Btw, Ask HN: I'm planning to setup a site hosted in linode540/slicehost512 and serve all but images/css/js in https, and expecting about 5k-10k page views a day. Will that slicehost/linode instance be enough?
- apinstein 16y agoYou can't really serve all but images in SSL as unfortunately browsers complain about this. We tried it but people constantly ask us why they get alerts (IE) and there is a "caveat" to the lock in Firefox. Sad but true.
- egoz 16y agoOuch! I use my own generated ssl certificate for development and doesn't realize this. Now, seeing where all https domains serve their image, I see that you are right. It saddens me, but thanks!