3 ms·
Sweet, this is basically want Lets Encrypt wanted, make the market go towards this free SSL model.
by homerguy69 10y ago
Sweet, this is basically want Lets Encrypt wanted, make the market go towards this free SSL model.
- Nadya 10y agoCompanies who aren't in the business of selling TLS [0] certs themselves have little excuse to not offer free TLS via Let's Encrypt. It's an advantage over any competitors who haven't set that process up. If your company does hosting - your company should provide TLS certs via Let's Encrypt automatically. [0] Can we start dropping the SSL part now? Generally SSL v2/v3 is disabled so it is all over TLS anyway.
- deleted 10y ago[deleted]
- user5994461 10y ago> If your company does hosting - your company should provide TLS certs via Let's Encrypt automatically. Correction: As part of the paid plan. Why give for free sometimes you can charge money for.
- JoshTriplett 10y agoIf you have a free plan at all, then the only reason TLS should not be a paid feature would be if you intentionally want to position the free plan as "don't take this seriously because you can't build anything production-quality on it".
- user5994461 10y agoThat makes sense for a hosting service. A lot of them works that way. Hosting a static free blog doesn't need TLS.
- JoshTriplett 10y ago> Hosting a static free blog doesn't need TLS. Many kinds of static content need TLS, including protection from MITM and protection from eavesdroppers. Static doesn't mean "not sensitive". (Leaving aside the reasonable presumption today that all content is potentially sensitive.)
- icebraining 10y agoConsidering the amount of crap ISPs have been known to inject into websites, I disagree. TLS isn't just for encryption, it also provides data integrity.
- Godel_unicode 10y agoThis is the correct answer. Use this reasoning.
- IgorPartola 10y agoYes it does. Stop spreading this misinformation because it is dangerous. Everything should be encrypted. I don't want people knowing that I'm reading your blog or what on it I am reading.
- Jach 10y agoNow who's spreading misinformation? HTTPS doesn't protect the fact you're reading a blog (the IP of the server will be observed, and typically the server name through the cert itself) and while one can't prove which URLs of the server you visited one can infer based on the amount of traffic sent.
- samb1729 10y agoThere's a pretty significant difference between someone being able to tell, for example, that you visited medium.com, and that same someone being able to tell exactly which blog post you read because the whole request is unencrypted.
- 10y ago
- nsgi 10y agoThere are ways of doing that without sacrificing security. Making TLS a paid-only feature makes no more sense than making CSRF protection a paid-only feature.
- hamandcheese 10y agoOn Heroku, TLS is enabled if you use the *.herokuapp.com domain, even on free plans. So really they are charging you if you need a custom domain and security (i.e. Something most businesses do need and most hobbies don't). Seems a like a reasonable and fair way to segment their market to me.
- JoshTriplett 10y ago> If you have a free plan at all, then the only reason TLS should not be a paid feature would be if you intentionally want to position the free plan as "don't take this seriously because you can't build anything production-quality on it". I only just now noticed a rather serious typo there, making that sentence confusing. Should have said "the only reason TLS should be a paid feature", which fits with the rest of the sentence.
- Nadya 10y agoBecause your competitors will do so and the paid plan should be to paying for bandwidth or storage space, not TLS. Now you just lost your lunch to competitors who aren't trying to nickle and dime their customers. >Hosting a static free blog doesn't need TLS. Completely wrong, although others explained why already.
- RKearney 10y ago> Can we start dropping the SSL part now? Generally SSL v2/v3 is disabled so it is all over TLS anyway. It's the same certificate though. So can we start calling them X.509 certs which is more proper than SSL or TLS cert?
- nailer 10y agoA bunch of folks have started calling the ones used for websites 'https certs' since 'https' actually appears in the browser UI and 'tls/ssl' is unwieldy.