7 ms·
CNN.com quietly turned on TLS/HTTPS over the weekend
I just noticed this. HTTP 301s to HTTPS. I say "quietly" because I can't find any official announcement.
- coolso 9y agoI wonder if they'll ever turn comments back on, too?
- overcast 9y agoThe internet, especially news, is a better place without it.
- kardos 9y agoSays a guy commenting on the internet?
- deleted 9y ago[deleted]
- coolso 9y agoI think most would agree - but come on, let's not go overboard. CNN has just as much a right to exist on the internet as anyone else.
- Antifragile1 9y agoWhat a fucking retard!
- eth1 9y agothey will not dare to. They are too dirty to allow that to happen.
- Nouser76 9y agoCNN.com used to be my go to website for logging into splash pages that were blocked on HTTPS websites. Now I have to find a new one!
- sp332 9y agoexample.com should be safe.
- gabrielwong 9y agoI've been using neverssl.com
- hitsurume 9y agoIs this a big deal? Pretty sure they did this because of SEO reasons
- HendrikR 9y agoSafari just joined the party in displaying a warning if the connection is not using TLS/HTTPS just like other browsers do.
- super_trooper 9y agoI was seeing this a couple weeks ago
- scrollaway 9y agoI've been seeing it for six months almost. Maybe https-everywhere was doing this but I also used to use CNN as a hotel WiFi sign-in gate so I noticed it back then. Funny how many people independently ended up in that same situation. How did y'all start?
- bhartzer 9y agoThey didn't move everything to HTTPs. There are still subdomains that are still HTTP, such as collection., money., go.cnn.com
- adam-ff 9y agoSearching for an announcement, I found an ironic result: http://money.cnn.com/2016/09/08/technology/google-chrome-flag-non-secure-sites/index.html http://money.cnn.com/2016/09/08/technology/google-chrome-fla... And, despite money.cnn.com being one of the Subject Alt Names on their certificate (as well as plenty of app, api and some staging domain names), that domain in particular rejects connections to port 443. Maybe their transition is incomplete and they're not ready to announce yet?
- tastyham 9y agoShit, they were my go-to page for signing into hotel WiFi. Where can I go to now?
- mopeloi 9y agoNeverSSL.com is my goto
- corin_ 9y agoI use ipchicken.com, works over http for public wifi signins, and has added benefit of showing me whether I’m connected to wifi/4g/vpn via IP’s reverse DNS.
- tompagenet2 9y agoI enjoy using http://www.stealmylogin.com http://www.stealmylogin.com as it seems apt (and works)
- jdlyga 9y agowww.neverssl.com
- tazard 9y agohttp://http.rip http://http.rip
- dajohnson89 9y agosorry for the stupid question, but how is https a bad thing? and what does this have to do with hotel WiFi?
- enzanki_ars 9y agoMost hotel wifi networks require opening a browser to connect. Once you open it, the first page you go to is redirected. Because a lot of sites default to HTTPS, that redirect is detected as a MITM by the browser, and prevents you from moving on. http://neverssl.com/ http://neverssl.com/ is an easy way to get to the portal without an issue. As noted on NeverSSL: > [...] it [...] means that if you're relying on poorly-behaved wifi networks, it can be hard to get online. Secure browsers and websites using https make it impossible for those wifi networks to send you to a login or payment page. Basically, those networks can't tap into your connection just like attackers can't. Modern browsers are so good that they can remember when a website supports encryption and even if you type in the website name, they'll use https.
- stevew20 9y agoStrange, given the numerous anti-cryptography articles they've published...