5 ms·
"Studies show [...] that users become blind to warnings that occur too frequently." So right now it would be counterproductive to mark all http pages as "not s
by sqren 10y ago
"Studies show [...] that users become blind to warnings that occur too frequently."
So right now it would be counterproductive to mark all http pages as "not secure". But it's the long-term goal.
- jakobdabo 10y agoThe majority of the big sites that people use (Google, GMail, Youtube, Facebook, Reddit, NYT, WaPo, etc.) are already being served using HTTPS. I think if a couple of HTTP sites an average user still browses start showing these warnings they will notice them. And what matters, the owners of those websites will notice them and will ask their "IT guy" hey "why our website is marked as insecure? I want a green lock like Gmail has".
- threeseed 10y agoAnd that IT guy will go well there isn't anything I can do about it. The user will then forever ignore it (because they like that web site) and the whole exercise is wasted.
- johndoe4589 10y agoTheir IT guy?? There are gazillions of people like me who have a blog, or some small project that has a small audience of tens to just a few thousand users. All these people now have to fork for SSL, or have to move everything to a different shared hosting that supports Let's Encrypt.
- the_duke 10y agoRight now, you can just put Cloudfront in between. It's free, and takes maybe 5 minutes to sign up and adjust your DNS entries. Of course relying on a provider that might cancel the free plan at any time is not ideal, but worst case you just have to revert your DNS and it's done.
- michaelmior 10y agoI assume you mean Cloudflare and not Cloudfront. While you could use Cloudfront, AFAIK there's no free option. (Aside from the usage you get as part of the AWS free but that is time-limited.)
- wjdp 10y agoAWS Cloudfront isn't free but costs pennies a month if you're not big.
- johndoe4589 10y agoI'm running a web app, isn't Cloudflare best for static / semi static content?
- helb 10y agoIt is, but it might work for your app, too – js/css/image caching at CF nodes helps a lot. Moreover, you can disable their cache/cdn features and use it only for SSL. They even have multiple modes, the "Flexible" one works even with no changes at your server at all. It obviously makes the CF<->server transfer insecure, but your users would still get a "green lock", if that's what you're after. This is from their in-settings help: https://www.cloudflare.com/a/static/images/ssl/ssl.png https://www.cloudflare.com/a/static/images/ssl/ssl.png
- icebraining 10y agoYour shared hosting service doesn't need to support Let's Encrypt, it just needs to allow you to upload a certificate. You can use https://gethttpsforfree.com/ https://gethttpsforfree.com/ to generate it.
- johndoe4589 10y agoThey want an "installation" fee. And then how does the renew process work?
- deleted 10y ago[deleted]
- icebraining 10y agoThe renewal is the same, follow the steps and you get a new cert. Keep the Account key and the CSR, so it's just a matter of copy-pasting. If they charge an installation fee again, you're probably better off paying for cert that lasts longer (not from Let's Encrypt) - you can get one that lasts three years for $15. Or just switch hosting providers :)