47 ms·
Life Is About to Get Harder for Websites Without HTTPS
- deleted 9y ago[deleted]
- milankragujevic 9y agoWith Cloudflare's first easy to use free SSL and later Lets Encrypt, I think it there are no more excuses for not being secure.
- thesmallestcat 9y agoCloudflare's free SSL is not secure.
- catshirt 9y agois not? or was not? honest question. care to elaborate for a noob?
- lambda 9y agoCloudFlare's "Flexible SSL" (https://www.cloudflare.com/ssl/ https://www.cloudflare.com/ssl/) offers encryption/authentication from CloudFlare's server to the client, but none from the origin server to CloudFlare's. Which means that is a vector by which the content could be sniffed or modified in transit. It's a "better than nothing" option, as there are a slightly higher number of actively exploited attack vectors that apply to the client to CDN connection than the CDN to origin server, such as "free" wifi that injects ads, malicious ISP DNS, and the like. But it's not actually secure, as the origin server to CDN connection could be tampered with, and just because there are fewer active attacks that would be likely to affect that connection right now, doesn't mean that someone won't come along later and hijack such a connection. CloudFlare offers other TLS options that do include encryption and authentication between the origin server and CDN, but they do require that you set up a certificate on your server, so if all you're trying to do is enable TLS (and don't care about the CDN), just installing a cert on the origin server and using TLS is probably a simpler option that using CloudFlare.
- catshirt 9y agogreat noob elaboration. much appreciated. :)
- prdonahue 9y agoWe encourage users to use Strict mode which requests and validates a certificate from the origin. It's great that shared web hosting providers and others are starting to make it easy to acquire and install a certificate, but that hasn't always been the case. EDIT: We also provide an API that will provision a free certificate for your origin: https://blog.cloudflare.com/cloudflare-ca-encryption-origin/ https://blog.cloudflare.com/cloudflare-ca-encryption-origin/. The certificate is optimized for communication with our edge (essentially just as small a chain as possible, as we don't need the intermediate to walk to the root). Either that or use certbot from EFF/Let's Encrypt.
- deleted 9y ago[deleted]
- justboxing 9y ago> is not? or was not? Troy Hunt (OP) discusses this at length in this post => CloudFlare, SSL and unhealthy security absolutism https://www.troyhunt.com/cloudflare-ssl-and-unhealthy-security-absolutism/ https://www.troyhunt.com/cloudflare-ssl-and-unhealthy-securi...
- milankragujevic 9y agoWell it kind of is if you setup a self-signed SSL cert on your server and use Full SSL (not strict).
- blfr 9y agoYou can setup a Let's Encrypt certificate on your server and use Full SSL (strict). It will also make switching away from Cloudflare in the future easier.
- jgrahamc 9y agoThat's right. Cloudflare doesn't try to lock people in with artificial constraints. Use Let's Encrypt for your origin. Very soon we hope to support Let's Encrypt completely for our main certs (once they have wildcard support).
- deleted 9y ago[deleted]
- LarryMade2 9y agoExtra cost of a static IP hosting (needed for domain registration) is a big factor, doubles the costs of my small website hosting.
- finnn 9y agoDomain registration? That certainly doesn't require a static IP... nor does any other part of deploying TLS.
- throwaway2048 9y agohttps://en.wikipedia.org/wiki/Server_Name_Indication https://en.wikipedia.org/wiki/Server_Name_Indication Any host that still requires a dedicated IP for https is woefully out of date.
- mjevans 9y agoIt's sadly not just the servers but also the clients... still you're right about that being a really long tail at this point. Edit: A quick search seems to indicate that the only typical consumer facing system that doesn't support SNI is IE on Windows XP. It's pretty safe to have a catch-all bucket that informs such users to use a modern, security patches including browser or to upgrade to a different OS.
- throwaway2048 9y agoAnything that cant do SNI isn't going to support TLS 1.1+ and wont be able to access a huge percentage of the web anyways. Eventually old clients have to be let go of, maintaining compatibility for them degrades everyone else's security.
- kvz 9y agoUnless you support both via e.g. https://jve.linuxwall.info/blog/index.php?post/2015/10/04/SHA1/SHA256-certificate-switching-with-HAProxy https://jve.linuxwall.info/blog/index.php?post/2015/10/04/SH...
- grecy 9y agoI'm running Varnish in front of wordpress and mediawiki.... sure I can make it all work with HTTPS, but it's going to be a PITA.
- chrsstrm 9y agoNot really. You put nginx in front of Varnish and terminate your TLS there. It's not that much more work. Hint: make sure you have an X-Forwarded-For entry in your nginx config. Your root location would look something like: location / { proxy_pass http://localhost:8082; proxy_set_header Host $host; proxy_set_header X-Real-IP $remote_addr; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; proxy_set_header X-Forwarded-Port 443; proxy_set_header X-Forwarded-Proto $scheme; } Assuming your Varnish setup was serving on 8082.
- LunaSea 9y agoLet's Encrypt's short expiration times make them too cumbersome to use.
- SquareWheel 9y agoThe point is to automate. If you're manually renewing them every thee months, then you're very much doing it wrong and it should be cumbersome.
- LunaSea 9y agoBut most people don't want or know how to automate. HTTPS is supposed to be used on very site but not every site is setup by a developer. That's a basic flaw that will make it problematic to have these kinds of HTTPS-only policies.
- SquareWheel 9y agoHaving done both, it's far easier to set up one of Let's Encrypts automatic tools than it is to install a certificate manually. End users won't be configuring their own servers anyway. At best they'll get a cPanel (which using AutoSSL, can then support Let's Encrypt).
- extra88 9y agoIf one can't handle setting up Let's Encrypt, they should host their content on a platform where others take care of things like HTTPS for them.
- chillingeffect 9y agoBit of a scare tactic. Page is an ad for Mr. Hunt's $299 course. It's all true. However, I would make the case for Pat Q. Mainstream feeling less alarmed by "Not Secure" messages than most HN readers. Note the Twitter example is from Mr. Hunt, not a random internet user.
- Operyl 9y agoHow is it a scare tactic? It's the reality, there's not much more room for an unencrypted web nowadays. Troy can feel free to advertise whatever he wants, and what he says is still true.
- peteretep 9y ago> Page is an ad for Mr. Hunt's > $299 course I read it and at the end was unaware he had a course, so I don't think this is true.
- chillingeffect 9y ago"a few months ago I published a new Pluralsight course on What Every Developer Must Know About HTTPS "
- skeletonjelly 9y agoIt's his MO. Every article of his is decently researched with lots of fluff, always points to another article of his, and always ends in some kind of conversion goal.
- laughfactory 9y agoTrue, but a man's gotta eat, and security is more and more critical these days. I don't begrudge him making a living while beating the drum of be-more-security-aware.
- skeletonjelly 9y agoTrue. He's well off already though. The article that seems to stick in my head is him spruiking a wifi extender he got for free so he can access wifi on his jetski at his jetty. https://www.troyhunt.com/how-i-finally-fixed-the-dodgy-wifi-on-my-jet-ski-with-ubiquitis-unifi-mesh/ https://www.troyhunt.com/how-i-finally-fixed-the-dodgy-wifi-... I can't bemoan how many times I've had poor wifi at my jetty ;)
- vmp 9y agoOff-topic: If only IPv6 adaptation would have as much momentum as HTTPS.
- cbhl 9y agoI suspect the big reason it hasn't happened yet is it would require ISPs to replace tens of thousands of dollars of hardware and it would increase support requests in the short term ("site XYZ is broken but it's fixed when I turn of IPv6").
- swift 9y agoIs the hardware you're talking about the network equipment controlled by the ISP, or the routers and modems in customers' homes? I'd be surprised if the former hadn't been IPv6-ready for many years now, but I can imagine many customers are still using ancient hardware left over from when they first signed up for service.
- tsomctl 9y agoIf you have cable, a number of providers have been making customers upgrade to the newest modem. A single old modem that doesn't support docsis 3 will slow down everyone in your neighborhood.
- curiousGambler 9y agoReally? Interesting... can you elaborate/provide some reading? I'm a software engineer with a smidge of basic networking experience so not completely clueless, but definitely inexperienced with DOCSIS and this sort of residential networking stuff.
- derefr 9y agoThat, and—unlike TLS—there isn't any class of business-destroying vulnerability whose easy solution is IPv6.
- lima 9y ago
- fatzombi_ 9y agowhat about self signed certificates? wouldn't it be great if these swebsites treated like http ones, without any security flags
- electrum 9y agoAllowing transparent downgrades of self-signed certificates would be a big security hole. For example, suppose I add the following to my website: <script src="https://cdn.example.com/awesome.js"> By doing so, I am requiring the script to be served securely. If we allow self-signed certificates, anyone could generate a self-signed certificate for example.com and serve a malicious script to my users.
- pdkl95 9y ago> Allowing transparent downgrades of self-signed certificates would be a big security hole. Automatically generated self-signed certificates should have replaced all plaintext HTTP 15-20 years ago. The big security hole was allowing passive surveillance, ISP-level page injection vandalism[1]/attacks[2]. The web could have been almost completely protected from several classes of attack a decade ago, but this stupid insistence on conflating protection from 3rd part eavesdropping or corruption during transit with the authentication of the server. These are entirely separate problems that do not need to be solved at the same time. > I am requiring the script to be served securely You're requiring it to be served over HTTPS, which doesn't necessarily mean "secure", because "secure" covers several different goals. You're also strongly trusting the PKI system. Do you trust all the certificate authorities your browser includes by default? Of course, because HTTP still exists, the initial request for the HTML that contains your <script> tag could be sent plaintext and thus modified during transit in many different ways. > serve a malicious script to my users. That can still happen without proper pinning, or if the local browser downgrades the request back to HTTP. Unfortunately this isn't particularly uncommon with corporate/school proxy, in-flight wi-fi services that forge certificates[3], and Superfish-style junk all removing both the encryption and the authentication provided by TLS. Regarding your specific example about loading Javascript referenced in an HTML document's <script> tag, the solution is to validate the data, not the server. The valid server can still send incorrect data. If you include hashes about a page's subresources[4], the browser can validate the integrity of the file it received. [1] https://arstechnica.com/tech-policy/2014/09/why-comcasts-javascript-ad-injections-threaten-security-net-neutrality/ https://arstechnica.com/tech-policy/2014/09/why-comcasts-jav... [2] https://citizenlab.ca/2015/04/chinas-great-cannon/ https://citizenlab.ca/2015/04/chinas-great-cannon/ [3] https://arstechnica.com/information-technology/2016/02/why-you-probably-shouldnt-be-doing-work-on-that-in-flight-wi-fi/ https://arstechnica.com/information-technology/2016/02/why-y... [4] https://www.w3.org/TR/SRI/ https://www.w3.org/TR/SRI/
- eliben 9y agoSerious question: if I just run a simple blog with static HTML hosted with Apache, do I really need HTTPS? Will I be penalized by not having it?
- saagarjha 9y agoIt doesn't look like it right now: > all websites with form fields served over HTTP will show a "Not secure" warning to the user As long as you don't have a form field, you should be fine.
- marksomnian 9y agoI believe the Chrome team has (or at least had) long term plans to mark all HTTP sites as actively dangerous, form fields or not. So, you'll be fine for now, but there will come a point when you will need to implement HTTPS.
- JonRB 9y agoMy understanding is that you will already be ranked lower on search engines. My main concern with this happening is that browsers are going to get a reputation for being 'alarmist', so when something really goes wrong, they won't be able to communicate it effectively.
- seanwasere 9y agoalarmist media gets the most clicks, perhaps browser developers see a new way to push products to people, bit like when your antivirus shows alerts in your screen all the time. they are essentially pushing there own products by flashing there logos in your face all the time.
- jaas 9y agoYou won't have confidence that your visitors see the content you serve as you intend because it can be modified in transit. Your visitors will be broadcasting at least the exact address of the pages they read on your blog, and are vulnerable to anything that gets injected into your traffic in transit (e.g. malicious script). Every website should use HTTPS. It's the right thing to do. It's not hard to do these days.
- idibidiart 9y ago"HTTPS Everywhere" is a knee jerk reaction to the Surveillance State which actually does nothing more than serve the Surveillance State by giving gullible folks the perception of security while allowing State actors clear-text access to supposedly encrypted traffic (MITM attacks via undermined CAs and Certificate Transparency is supposed to help but c'mon... who are we kidding) Waiting for your 200 down votes.
- URSpider94 9y agoWhat's your recommendation? I don't think anyone is saying this is the be all and end all. I'd rather be susceptible to hacking by nation-states while protecting myself from all the 1337 hax0rs out there.
- idibidiart 9y agoBrowser vendors can guarantee privacy the same way that the best (independently audited, opens source) encrypted messaging clients can guarantee privacy. It's not rocket science, but it's never been a goal of browser vendors.
- URSpider94 9y agoCan you provide more background on what you feel that messaging clients are getting right, but browsers are missing?
- idibidiart 9y agoI can use Signal to communicate to another user without being subject to surveillance. But I cannot use my browser to chat with another browser user with the same degree of immunity to surveillance. Let's say some xyz website's server was just another Signal client. I can talk to it from my Signal client in a way that is not subject to State surveillance. But I can't do that using HTTPS as my security model. As to how Signal does it... Read their blog.
- kylehotchkiss 9y agoBleh. Wish I could use ssl on my GitHub pages site with custom domain.
- unmole 9y agoI do exactly that with Cloudflare.
- reustle 9y agoAccording to the comments above, it's not exactly secure
- prdonahue 9y agoThose are uninformed comments.
- icebraining 9y agoThose comments are saying that because the last hop (Cloudflare → Github) will still be unencrypted. You may disagree that it doesn't make it insecure, but that doesn't mean they're uninformed.
- Santosh83 9y agoThe FULL option in fact requires HTTPS even for the last hop. It just accepts any certificate which isn't as good as only accepting a valid certificate. But the last hop doesn't have to be clear-text any more.
- icebraining 9y agoRight, but if someone can snoop the connection between Cloudflare and your server, chances are they are in control of some intermediate machine and can MITM, injecting their own self-signed cert.
- 9y ago
- misterAxiom 9y agoThis is mean-spirited and stupid. This person should not have wasted time writing this. Edit: Why the downvotes? This is a terrible article. It is a ridiculous attack on HTTP and the open web.
- y0ghur7_xxx 9y agoI hope lans are exluded? I'm scared that I will get security warnings everywhere in my lan. - when I log in to my webcams it says the connection is not secure - when I log in on my nas it says the connection is not secure - when I log in on my router it says the connection is not secure - when I log in on the web interface of mythtv it says the connection is not secure - when I log in on my self hosted gitea instance it says the connection is not secure - when I log in to my self hosted nextcloud it says the connection is not secure - when I log in to the configuration page of my toaster it says the connection is not secure All these things are on my lan, and on most things there is no way to install a tls cert on them, nor would I want to do that. Firefox already nags me that the connection is not secure when i enter a username and a password in any of those sites.
- dx034 9y agoI'd hope LAN is included because while you use some services at home, most people will primarily use LAN services in public Wifis. It would be sensible to have HTTPS used there. They'd have to come up with a new idea of login pages (currently most systems MITM http requests) but otherwise it would make sense if you get a warning when you access pages on your hotel/in-flight Wifi without encryption.
- y0ghur7_xxx 9y ago> most people will primarily use LAN services in public Wifis [citation needed] - I would say most people will primarily use LAN services in private home/corporate networks. But I don't have a citation either. It's different use cases. Maybe one needs the warning, the other one not. But putting the warning on everything and overload the user with them is not the right solution. Using a self signed CA is a pity, because installing it on every phone, tablet, laptop, tv, pc, ... is cumbersome in a home network, and making all hosts public and depending on an external CA for local resources to not get scary warnings can not be the right solution either.
- dx034 9y ago> [citation needed] - I would say most people will primarily use LAN services in private home/corporate networks. But I don't have a citation either. Sorry I don't have a citation here. But looking at my coworkers and family, none of them uses services in their home LAN. Most won't even know how to access the router. On the other hand it's very common to use Wifi in public transport (at least here in London for the tube), airports, trains and hotels. Few people consider security when using these hotspots, making sure that SSL is enabled for all pages would be an improvement.
- cryo 9y agoHTTPS is pain in the neck and _currently_ I hate it from the bottom of my heart. TLTR: if you have a commercial service or device running in a local network forget HTTPS and service workers, use HTTP and HTML5 appcache. -- RANT starts here -- It would be lovely when every website and webapp uses HTTPS. But for a significant amount of them it's just not f..... possible without driving users completely insane. If the HTTPS server doesn't (and never will) have a public domain forget about encryption and security, forget about using service workers. The following examples can't, by the love of god, ever provide HTTPS without completely f..cking up user experience due self signed certificates warnings: 1) internal corporation services, websites and webapps. 2) services that run in a local private network like on a Raspberry Pi. 3) webapps which are served via public HTTPS website, but need to talk via CORS to local unsecured services, like to a Philips hue bridge, or any other IoT device which is in the local network but only provides HTTP. These will enlight the users with a shiny mixed-content warning. .... JUST use self-signed certificates, they said. NO. For normal users the UX of self-signed certificates is just non existent, it's a complete mess! It will scare the sh't out of users and will almost always look like your service is plain malware. It looks much more secure to serve a good'ol HTTP site with no encryption at all.
- sgift 9y ago> 1) internal corporation services, websites and webapps. For this use case companies usually provide an internal CA, which signs their certificates and is trusted by all company machines. We have various customers which do this and it works just fine.
- jakobbuis 9y agoThis fails utterly when you can't control your clients. My student society for example ran into this problem. Students bring their own laptops and installing our root certificate on all of them is infeasible (if they even would allow us to do so). As a consequence, we need to expose critical internal services on the public internet, some of which contain private user data.
- 9y ago
- sebcat 9y agoI wish people would stop equating "secure" with "HTTPS".
- Aissen 9y agoThat's not what's done. "No HTTPS" is equated with "non secure".
- sebcat 9y agoHe also claims that Quantas "secured their site" by adding HTTPS to their login page, and that serving sites over HTTPS is "secure by default"
- willstrafach 9y agoThis is true. I can intercept your username/password during login by being in close proximity to you if you are logging into their website over plaintext HTTP. Not possible if it is protected by TLS (HTTPS).
- ko27 9y agoWell that's what the S in HTTPS stands for. I am pretty sure that anybody who knows the difference between HTTP and HTTPS also knows that "security" is not binary.
- sebcat 9y agoSince this guy is equating "secure" with "HTTPS" in some of his statements, would you say that he does not understand that security is not binary?
- TekMol 9y agoHow hard is it to provide HTTPS these days? Say you have a plain Debian 8 install, running a typical LAMP stack serving a single domain. If you want to make it use a LetsEncrypt cert and serve the domain over HTTPS - what would be the minimum number of steps on the command line to make it do that?
- ezequiel-garzon 9y agoSomething like (assuming you've reviewed the terms of service): apt install letsencrypt letsencrypt certonly -d example.com -d www.example.com -m you@example.com --agree-tos And then add a weekly cron job with: letsencrypt renew You need to stop your server for these actions, though I'm sure there are ways to avoid this.
- TekMol 9y agoThere is no package "letsencrypt" in the repos of a standard Debian 8 installation.
- ezequiel-garzon 9y agoMy apologies, then. I mistakenly keep assuming Debian/Ubuntu similarities...
- jws 9y agoIt is "certbot" in Debian 9. Maybe 8 too.
- jefozabuss 9y agohttps://www.digitalocean.com/community/tutorials/how-to-secure-apache-with-let-s-encrypt-on-ubuntu-14-04 https://www.digitalocean.com/community/tutorials/how-to-secu...
- tajen 9y agoA dozen in non-interactive mode; less than half in interactive: Non-interactive: install Certbot, copy the config file, run certbot, add a crontab for renewals, configure your nginx to see the certificate.
- a_imho 9y agoI deploy ssl on all my sites, but imo the article is way overestimating the importance of browser notifications.
- anilgulecha 9y agoUsers are tuned to seeing green icon, and secure as trustworthy. This is over a decade of UX towards these. Suddenly seeing "Not secure" will definitely have an impact on engagement. (I know we're both guessing -- we'll have to wait for concrete numbers to make a call). I'd mark the engagement change at around 10%, and 20% for any site that is login/payments related.
- return0 9y agothey have been seeing that for months now ( i see it often too on sites that are slow to change). I have not heard anyone complaining about loss of traffic. It's becoming transparent to the users, imho, like the EU cookie prompt.
- anilgulecha 9y agoIt's not red yet. It will look like this eventually.: https://www.wordfence.com/wp-content/uploads/2017/01/blog-image-2.png https://www.wordfence.com/wp-content/uploads/2017/01/blog-im... , which will be a stronger negative signal.
- wfunction 9y agoHow is a gateway serving a configuration page at 192.168.1.1 to internal users supposed to eventually get an HTTPS certificate for that address...?
- teddyh 9y agoEasy. Get a certificate for some name, say foo.example.com. Point foo.example.com, in your internal network's resolver, to 192.168.1.1. Use foo.example.com in the browser instead of 192.168.1.1. Done.
- wfunction 9y agoWho is supposed to do this exactly? Me the consumer who buys a router, or me the manufacturer of said router? (router/access point/whatever it's called...)
- gcp 9y agoThe manufacturer can set up a public DNS entry I think. i.e. it'd be config.linksys.com and that'd point to 192.168.1.1, but have a certificate that matches the one on the router.
- wfunction 9y agoOK, and (1) how are you supposed to trust that the manufacturer won't get hacked one day (or whatever) and the IP address won't change to something external/malicious? (2) what if I don't have an internet connection and don't have a DNS server on the gateway that can reply to such a query?
- lmm 9y ago1) If you trust them to write secure router firmware you can trust them to keep their HTTPS certificates safe - the former is a lot easer than the latter. 2) Router intercepts all DNS requests and responds with its own IP, responds to HTTP calls with HTTP 428, like already happens and like OSes already deal with appropriately.
- seanwasere 9y agohttps isn't the only way to secure data, you can still secure messages without using https so I think this wont last and just make alternative methods more visible
- KevinEldon 9y agoHTTPS gives your ISP less of your information to collect, analyze and sell to advertisers which in turn protects the value of Google's information about you. I think the changes to Chrome are well-intentioned, but can't help but smile at how this side-effect favors Google's business.
- epalmer 9y agoI have been anticipating this but have had better things to spend my limited time on. I have more than 135 sites I need to convert to https and they are load balanced. I don't think letsencrypt handles load balanced sites yet. My management is against wildcard certs. This might push them over the edge in favor of wildcard certs.
- laurencei 9y agoI use LetsEncrypt on a load balancer without issue.
- epalmer 9y agoDO you have a url for documentation that shows how to set up the certs? Our certs are on each web server and not in the load balancer. I suppose we can also put the certs into the load balancer but I don't have control over that. Edit: typo
- extra88 9y agoYou can have a single cert with all 135 sites' domain names in it. A wildcard cert may be preferable if the list of domain names frequently changes.
- epalmer 9y agoThanks. I hadn't yet considered this.
- userbinator 9y agoI'm most worried about the "long tail" of often very interesting, useful, and rare content (a lot of it from a time when the Internet was far less commercialised) that is unlikely to be hosted on HTTPS, and whose owner may have even forgotten about or can't be bothered to do anything about, but still serves a purpose for visitors. The "not secure" will drive a lot of visitors away, and even lead to the death of many such sites. Imagine someone who knew enough to set up a site on his own server a long time ago and had left it alone ever since. Maybe he'd considered turning it off a few times, but just couldn't be bothered to. Now he suddenly gets contacted by a bunch of people telling him his site is "not secure". Keep in mind that he and his visitors are largely not highly knowledgeable in exactly what that means, or what to do about it. It could push him over the edge. ...and then there's things like http://www.homebrewcpu.com/ http://www.homebrewcpu.com/ which might never have existed if HTTPS was strongly enforced all along. I understand the security motivation, but I disagree very very strongly with these actions when it also means there's a high risk of destroying valuable and unique, maybe even irreplaceable content. In general, I think that security should not be the ultimate and only goal of society, contrary to what seems the popular notion today. It somewhat reminds me of https://en.wikipedia.org/wiki/Slum_clearance https://en.wikipedia.org/wiki/Slum_clearance . (I also oppose the increased centralisation of authority/control that CAs and enforced HTTPS will bring, but that's a rant for another time...)
- Matt3o12_ 9y agoUnfortunately, if the owner of the content is not interested in keeping this site up, the content will be lost sooner or later anyways. He probably also does not bother to install security updates and he will most likely stop paying the bills at some point (domain name, hosting server, etc). Installing LetsEncrypt is not much work and he might be motivated if a lot of people ask him. If he is really not interested, it is probably best to archive the website to a real archive and hope they make sure they content remains available. Unfortunately this also means that the archive will no longer be found on google or most other search engines. It is really a shame that there is no work on google's side to make sure archived content can be found among other search results.
- 9y ago
- gator-io 9y agoHere's another take on how much of the web is HTTPS: https://truemarketshare.com/report?id=https https://truemarketshare.com/report?id=https
- makecheck 9y agoI hope they did some user testing to see how people actually behave in the presence of such warnings but in my experience it does nothing. Worse, it's in an environment that is already rife with little messages in corners trying to get your attention (ads) so users may be more "blind" when browsing than usual. The success of "Let's Encrypt" suggests that a key part of the problem wasn't a lack of user complaints about security. Rather, it was a lack of a sane model (both technically and economically) for setting up and maintaining certificates. In the end, people maintaining sites already had 100 other things to worry about and weren't going to get around to HTTPS with anything less.
- daxfohl 9y agoHow about a warning in Chrome that says "You're about to use Chrome to visit this website, and thus send everything about yourself to Google to do whatever they want with", for all websites staring in Chrome ~67?