3 ms·
HTTPS is a pain compared to HTTP, and I should not be pressured to use it, especially if I am on an internal network. Lets Encrypt has made it much easier, but
by unqueued 8y ago
HTTPS is a pain compared to HTTP, and I should not be pressured to use it, especially if I am on an internal network. Lets Encrypt has made it much easier, but it is still a significant and unnecessary barrier. And as helpful as things like the Lets Encrypt bot is, it still cannot be relied upon.
And anyone who doesn't think we are being spied upon is bonkers. It doesn't matter how secure HTTPS is, because there are so many other ways we can be monitored.
- shakna 8y ago> And anyone who doesn't think we are being spied upon is bonkers. It doesn't matter how secure HTTPS is, because there are so many other ways we can be monitored. HTTPS doesn't guarantee that, and certainly isn't state-actor proof, but if state actors are your concern, you need more than HTTPS, not less. What it does, is ensure nobody messed with the data before you get it. The browser indicates that to you. Basically: HTTP - Sir, are you aware someone may have changed what is in this enevelope? HTTPS - Sir, this letter has/not been tampered with.