11 ms·
Kinda like how your antivirus tells you about how the formidable threats it saved your ass from today? Or like "did you know your house COULD have been ransack
by johndoe4589 10y ago
Kinda like how your antivirus tells you about how the formidable threats it saved your ass from today?
Or like "did you know your house COULD have been ransacked today, but it didn't happen!!"
Now all my users are going to hear that my site is insecure, when nothing at all changed.
How long ago did they announce that? I think just a couple months? They should have announced this much sooner.
It's going to hit me hard as my site is pretty niche and driving even more people away is the last thing I hoped for :( My shared hosting doesn't offer Let's Encrypt, and makes me pay to "install" a free certificate anyway. So I have to move everything to a different web host.
- michaelmior 10y agoIt may not be an option for you, but you could consider using a free proxy service such as Cloudflare.
- bphogan 10y agoSeconding this, because this is what I do for one of my projects.
- angry-hacker 10y agoWhich is not really a true https, depends on your view, but the flexible plan is not encrypted to the source server as one might expect. But if it's possible to set up things that way, it is https, i guess.
- bsuh 10y agoWith the caveat that while the password will be encrypted from the browser to Cloudflare, it will still be transmitted as plain text from Cloudflare to your own server if your server doesn't support HTTPS. So it's an improvement but not entirely a fix.
- Latty 10y agoActually, Cloudflare offer you certs they sign (which wouldn't be trusted by others, but they verify), that you can use to encrypt from the server to them. You still have to trust Cloudflare, but it's not plain text from cloudflare to your server. If you mean the case where you literally can't serve under HTTPS, it's not just getting the cert that is the problem, in most cases running a local proxy of something that will would fix it, although I accept there are cases (cheap shared hosting, I guess) where that's not an option.
- jensvdh 10y agoWouldn't he still have to install the Cloudflare certs on his server then? In that case why not get LetsEncrypt?
- Latty 10y agoIn some cases you have the ability to add certs, but not to run the LetsEncrypt software (e.g: shared hosting) - with the short expiry date on LetsEncrypt certs, doing it manually is error-prone.
- baby 10y agoSo what? It's the harsh reality of unsecure http. Maybe your website has some important information and the user is just unaware of the dangers when entering his credentials on your website. Good for him, now firefox is warning him. He can choose to continue or not. Fortunately, if your website doesn't really hold any sensitive information then the user will go forward.
- oh_sigh 10y agoWhy do you have a password field on a http site?
- johndoe4589 10y agoLike every other person who started a forum some years ago or a wordpress blog you mean? Do you think web hosts offer SSL by default? NO they don't. Duh. That's what is annoying in these comments. Everyone seems to shrug like SSL is standard feature nowadays, except is isn't.
- lucideer 10y agoThat's the point. SSL/TLS is a standard feature nowadays. If you're a web host and you don't support certs or charge some unreasonable fee for adding them (and I'm well aware there are far too many of these out there), then you need to be losing business fast. Your customers should be moving to better competitors. This measure just accelerates this process.
- johndoe4589 10y agoTrue, it's just the transition atm is a bit painful. My host is asking ~80 USD for multi domain SSL. It's not that bad, but they don't support Let's Encrypt yet afaik. Are they aware of this and trying to cash in on people who don't want the hassle of moving their sites? On the other hand, if I buy there is none of that "auto renew" business...
- Operyl 10y agoErr, I work for a web host and we offer SSL by default as part of the onboarding. Speak for yourself :).
- mikeash 10y agoYou're leaving your users vulnerable because you can't be bothered to do things correctly. You are not the wronged party here, they are, and you're just finally being pushed into doing it right.
- 10y ago
- caconym_ 10y agoI am not a security expert, but as I understand it, passwords sent in the clear are vulnerable to being intercepted. Even if users of your site don't have much to worry about from those accounts being compromised (this may or may not be true), lots of people use the same password for more than one login, so their accounts on other sites could be compromised too. That's definitely a significant security risk, even if it wasn't being explicitly labeled before now. It sucks for independent website operators like you, but I'd probably blame your hosting for making it difficult to secure your site rather than browser vendors for protecting their users.
- johndoe4589 10y agoI know I guess I just have to vent some frustration. Time to move on I guess. Does anyone have good hosting suggestions for a web app that has a 1GB database and a few thousand active users? I can only afford ~10-20 EUR a month on shared hosting atm.
- techwizrd 10y agoHave you tried Amazon Lightsail or Digital Ocean? Both of them give you more than a paltry 1 GB for their $5/mo plans.
- fastball 10y agoSeconding DigitalOcean. You can get a 20GB SSD + 1000GB xfer for $5 a month.
- kuschku 10y agoRecommending against DigitalOcean: https://gist.github.com/justjanne/205cc548148829078d4bf2fd394f50ae https://gist.github.com/justjanne/205cc548148829078d4bf2fd39... TL;DR: Too expensive. (And, additionally, they tend to fuck over customers who paid for their money. "100$ free credit!". "You only need to pay 5$ to activate your free credit!". "Sorry, but because you didn’t use it, we removed your free credit!")
- mike-cardwell 10y agoYes. One of the positive aspects of this change is that it punishes the people who are either unable or unwilling to migrate to SSL.
- nathanaldensr 10y agoYour site's server is just one node in the chain of nodes between your server and the browser. Any one of these nodes could be malicious and tamper with the data in either direction. In other words, this isn't about just your node, it's about all nodes.
- IanCal 10y ago> Now all my users are going to hear that my site is insecure, when nothing at all changed. Correct, nothing has changed, it has always been insecure.
- inlined 10y agoShameless plug (since I work on Firebase) but if your site works on static hosting + BaaS, Firebase Hosting will give you free SSL + CDN support.
- godzillabrennus 10y agohttp://www.Netlify.com http://www.Netlify.com gives a free tier away with static HTML hosting + ssl + cdn as well.
- Chyzwar 10y agoMove your site.... Your negligence pose security risk to your users, they should be warned.
- twblalock 10y ago> Now all my users are going to hear that my site is insecure, when nothing at all changed. You're being pretty irresponsible if you aren't using SSL for passwords. You users should be told that your site is insecure, because it is. You should care more about the security of your users. If your hosting does not allow SSL, you have an obligation to change hosts for the safety of your users. If you aren't willing to do that, you're negligent and you should stop doing business with the public. This is a huge red flag. If you really don't think SSL is important, it raises disturbing questions about your approach to security in general. Which other standard security practices have you ignored? Are you using strong hashing for passwords? Are you properly handling input to prevent SQL injection?
- wfunction 10y ago> You're being pretty irresponsible if you aren't using SSL for passwords. So you're gonna tell me the owner of this site is irresponsible because it has a page with a password field that is not using SSL? http://www.w3schools.com/html/tryit.asp?filename=tryhtml_inputpassword http://www.w3schools.com/html/tryit.asp?filename=tryhtml_inp... How can you make any claim without having any idea what (if anything) the password is protecting?
- lostsock 10y agoThe password form on that page _IS_ insecure and it's good that the user is given information about that. They can then make the decision about themselves about the lack of security and how it effects them and the page they are on.
- twblalock 10y agoAre you seriously suggesting that a password field in an online code editor on an HTML tutorial site is comparable to the situation we are discussing here?
- madeofpalk 10y agoThe point is the result is the same - Chrome will flag that page is insecure.
- Sir_Substance 10y ago>Or like "did you know your house COULD have been ransacked today, but it didn't happen!!" >Now all my users are going to hear that my site is insecure, when nothing at all changed. I'm not sure you should be allowed to drive a webserver.
- NTripleOne 10y agoI'm not sure what the "driving" equivalent is for a battleship, but I'm pretty sure you do that to a server, not drive it. Commandeer?
- Sir_Substance 10y agoCommandeering web servers will probably get you arrested ಠ_ಠ I don't know what you do with a battleship. Helm it, maybe?
- NTripleOne 10y agoNo no, you only get arrested for commandeering next to another server and then boarding it.
- Vendan 10y agoCommandeer: Verb: take possession of (something) without authority. Sounds like you'd get arrested for that....
- renownedmedia 10y agoThe market demand will naturally require that all shared hosts start offering some sort of free HTTPS as webmasters such as yourself will simply be required to migrate somewhere where $hosting + $HTTPS is cheaper. This means shared hosts may start integrating with services like Let's Encrypt to save costs. In fact you could be proactive and announce to your shared host that for this reason you will be relocating. Let them know there will be a trend of other webmasters relocating for the same reason. As more and more website features (passwords, geolocation) start requiring HTTPS by browsers we will naturally approach the point where HTTPS is free and ubiquitous, at which point everybody wins. Also, you've had a one year notice that this was going to happen: https://blog.mozilla.org/tanvi/2016/01/28/no-more-passwords-over-http-please/ https://blog.mozilla.org/tanvi/2016/01/28/no-more-passwords-...
- johndoe4589 10y agoI agree. I don't think I'm going to tell them until after I moved though :p In any case they are hostgat0r and while the service is good overall, I hear they've been bought and it's not quite as good as it used to be. They gave me SSH, and even moved server when my site was being a bit sluggish (optimized the queries since)... so hmm. I genuinely don't have bad things to say about the hosting performance itself. But the documentation on their site is so bad, it alone makes me want to move on. Tired of spending hours trying to find the procedure to do this or that. And their live chat tkes forever to reply. Matter of fact, they require a fee for an external certificate, and then apparently you have to buy a static IP too. So another option is to upgrade the shared hosting plan, to the one that has a SSL bundled in. But.. then it works only on one domain AFAIK, so if my app also has a forum , I still need a second certificate! WHat if I want an API on another subdomain like api.foobar.com ? Yet another certificate. So I think I'll just have to move to a Let's Encrypt aware hosting.
- _Chief 10y ago>Now all my users are going to hear that my site is insecure, when nothing at all changed. Nothing's changed: Your site really is insecure, it's just that now users know.
- __derek__ 10y ago> How long ago did they announce that? I think just a couple months? They should have announced this much sooner. A year ago.[1] [1]: https://blog.mozilla.org/tanvi/2016/01/28/no-more-passwords-over-http-please/ https://blog.mozilla.org/tanvi/2016/01/28/no-more-passwords-...
- sametmax 10y agoYour site IS INSECURE. Nothing at all changed because it was, and now the user can just see it.
- Cthulhu_ 10y agoIn my country and probably a lot more, you'd be held legally responsible if by any means customer data would leak out. Be it stuff sent over a wire unencrypted, or an account with administrator access being compromised due to unencrypted password transfer. I dare you to go to a hacker or security conference once, just for kicks. Connect to any wifi there, log in. See what happens.
- johndoe4589 10y agoI don't have "customers" though. I thought this was implicit but maybe I needed to clear that up. Sure makes no difference to security. But that is the consideration when Google pushes everyone to have to buy SSL, even those who just have a hobby. I've just been venting frustration a little bit as to seeing the web change from the playground it used to be to a much more regulated thing, but so it goes. Times change :)