3 ms·
This is likely an organizational, rather than a technical problem. Having worked for large media organizations, often different parts of the site are different
by kaspm 10y ago
This is likely an organizational, rather than a technical problem. Having worked for large media organizations, often different parts of the site are different deployable applications that share only a hardware device or small nginx or haproxy layer if they're on the same subdomain. It may be that in order to enable SSL on all parts of nytimes.com you need to affect ssl termination at a higher layer on a number of different servers/deploy locations which requires time and testing.
It's also possible that terminating the SSL and then passing through unsecured traffic lower in the stack is not ideal due to where the different parts of the site are hosted - e.g. passing traffic unsecured back and forth between private DC and public cloud.
Note: All speculation based on having implemented SSL migrations at large media companies.