3 ms·
This is a really stupid move. There are plenty of instances where websites do not need to use HTTPS, like simple static websites for small businesses that do no
by amgin3 9y ago
This is a really stupid move. There are plenty of instances where websites do not need to use HTTPS, like simple static websites for small businesses that do not collect personal user information. This is going to cause a lot of confusion and outrage when it is implemented.
- orangecat 9y agoThere are plenty of instances where websites do not need to use HTTPS No there aren't. like simple static websites for small businesses that do not collect personal user information Until the connection gets MITMed to return a fake login page.
- gmueckl 9y agoWhat login page? Your typical company website just has a few pages of text without any active elements. Forcing those to buy SSL certificates creates just another artificial barrier to entry.
- dredmorbius 9y agoWhatever login page the attacker wants to present. They're betting percentages. Google. Amazon. sac.mil. fed.gov. Whatevs.
- throwaway2048 9y agoPlease tell me a way to enable https for local LAN only devices that does not involve me MITM'ing every connection to them..
- ksk 9y agoThis centralizes publishing rights to browser vendors & security cert vendors. I don't want to take permission from any third-party before publishing content on the web. In any case, its rather rude of you to presume to know what people should think about this topic.
- ridiculous_fish 9y agoHTTPS remains difficult to deploy for non-SWE web designers (i.e. the classic "webmaster" role).
- imhoguy 9y agoActually have to disagree with that. Currently "free SSL cert" is becoming part of every managed web hosting offering.