5 ms·
I think this comment about the extra hassle is worth thinking about in the context of an open internet. If you're a generic human being and want to do somethin
by throwaway420 10y ago
I think this comment about the extra hassle is worth thinking about in the context of an open internet.
If you're a generic human being and want to do something like create a little blog or share some artwork online or whatever, any little extra barrier or complexity is just a big pain in the butt that discourages you from doing that. I think this trend towards https is a factor in subtly encouraging people to just sign up up for one of many walled gardens out there in Facebook/Tumblr/Twitter/whatever because it's a lot less work and that's a bad thing for a free and open web in the long run.
- dispose13432 10y agoIf you're not running your own VPS (which you shouldn't for a little blog), then your host should take care of this for you.
- seanwilson 10y agoI agree with avoiding a VPS when you can. I think e.g. Digital Ocean + Let's Encrypt is just way too low level to be toying with when there's lots of hosting services that let you work at a higher level of abstraction where they deal with all the SSL details for you (e.g. GitHub Pages, Netlify, Heroku).
- shakna 10y agoGitHub Pages doesn't handle SSL for custom domains. The usual workaround is to throw Cloudflare in front of it, but the Cloudflare->GitHub link is still out in the open, and unencrypted.
- dispose13432 10y ago>GitHub Pages doesn't handle SSL for custom domains. That's a problem of GitHub, not of TLS
- shakna 10y agoPrecisely.