20 ms·
Encrypted web traffic now exceeds 90%
- chrisweekly 7y agoAwesome! Any idea how much of that is attributable to LetsEncrypt and HTTPSEverywhere?
- tomschlick 7y agoIt's probably more attributed to browsers marking non-https as 'Not Secure' than anything but LetsEncrypt definitely has had a substantial impact to make that change possible.
- SteveNuts 7y agoAlso Google mentioned they would begin ranking HTTPS sites higher.
- StartupTree 7y agoThat was always a false duck.
- SlowRobotAhead 7y agoPretty much this. I ran into a local store taking credit cards awhile back, no TLS, weird, so I go to the store owner in person. I explain the problem and he insists that can't be the case, he's mad at me. "See! It's got a lock on the website!"... on the homepage. I direct him to the store and now it says Not Secure. That did more to explain the situation than my attempt at TLS and HTTPS and Certs. He was able to call his web guy and say "It says not secure, Jerry! Fix it". It was such a simple addition to (at least in Firefox) use the words Not Secure that it's crazy no one thought of it before.
- JoshTriplett 7y agoIf that doesn't work, there's also the argument that "credit card providers require it, and could stop you from taking credit cards until you fix it".
- SlowRobotAhead 7y agoYou're right, but didn't have to. This guy when he could get past being mad at me knew that was against the rules. Also even if it was allowed, no one wants to shop at a place that says Not Secure. Side topic, but I've been trying to explain to our terrible CFO for years that PCI / PCI DSS is a real thing. He thinks that's the type of regulation that only giant companies have to deal with.
- toomuchtodo 7y agoFeel free to report your org to your merchant processor if necessary if you're not meeting compliance requirements and think you can get away with it without compromising yourself.
- icedchai 7y agoEven if it says "secure", that doesn't mean it really is. I worked at a place in the 90's that hosted a some sites taking credit cards through HTTPS. You know what they did? They sent emails, in clear text, to people at the store that would enter / process the cards manually.
- paulddraper 7y agoEven scalier than PCI compliance mumbo jumbo is customers not giving you any money.
- Avery3R 7y agothis is what gave us the pay.reddit.com loophole back when reddit https was for people with gold only
- clairity 7y ago
- JoshTriplett 7y ago> It's probably more attributed to browsers marking non-https as 'Not Secure' Browsers couldn't have done that if https wasn't free and simple for servers.
- mr_woozy 7y agoNever thought I'd see a world where that was the reality, nice to appreciate really.
- patrickmcnamara 7y agoI don't think any of my personal websites be HTTPS without LetsEncrypt. It's great for that use case.
- zamadatix 7y agoThere was a link a month or two back that showed Let's Encrypt is used by 30% of domains but if this is by volume of data not domain share then it'd be a lot less than 30%.
- mikece 7y agoIs a LetsEncrypt certificate "just as secure" as other certs? I have to imagine the answer is "no" simply because LetsEncrypt is free and the other certs aren't -- what more do you get by paying for a cert?
- a13n 7y agoIt is just as secure, you get nothing more by paying.
- deaps 7y agoSo for my personal projects, I use lets encrypt. As far as I know (and I could be wrong now, haven't checked in a while) - their certs are only good for 3 months. Which is simple enough to get around - run a script on your box that updates the cert every 90 days automatically. At work, we use a paid certificate that is good for a longer period of time (normally a year). So that's one benefit to paying, I suppose. As far as encryption technologies and security, the traffic encrypted by a lets encrypt cert is just as secure as the traffic secured by a paid-for CA signed cert.
- sadfklsjlkjwt 7y agoUsually you set up auto-renewal with lets encrypt. Easier than remembering to renew every year.
- anewaccountaday 7y agoThey have a built in command for their 'certbot' cli now that you can use to have your certificates update automatically. (It's been a bit sinse I went through it but I think it may be as simple as a extra flag in the command to generate the inital cert)
- taftster 7y agoThe fact that Let's Encrypt certificates expire quickly is a feature, not anything to do with paid vs. non-paid. Let's Encrypt could have just as easily generated certificates good for a year or more. But the point of Let's Encrypt is to force you to do this in an automated way, using scripts like you suggest. You're not getting around anything. The choice was by design. https://letsencrypt.org/2015/11/09/why-90-days.html https://letsencrypt.org/2015/11/09/why-90-days.html
- gator-io 7y agoThe whole reason we started tracking HTTPS vs HTTP was because of LetsEncrypt. Love that they broke the need to pay ridiculously overpriced fees to generate certs.
- amyjess 7y agoI'd imagine that a lot of this is attributable to Firesheep calling attention to how anyone on a public Wi-Fi network could snoop on your Facebook traffic. Most of the major websites fast-tracked HTTPS shortly after that.
- cdine 7y agoThanks! That was the goal. For those who aren't familiar, the original slides and our response blog posts are still up: https://codebutler.com/projects/firesheep/ https://codebutler.com/projects/firesheep/
- intolerabletech 7y agoIt is amazing how HTTPSEverywhere has revealed how incompetent people are regarding TLS/SSL. I can't count the number of times I've seen the extension page during sign-ups or logins. Oracle Cloud just triggered it the other day during signup and initial login. Most times when I email, asking why an email marketing link, or an embedded token-login email link sends me through an HTTP URL, the person on the other ends tells me they don't know and that's unexpected, or a result of out-sourcing their marketing/email/whatever. In one case, their marketing mail provider supposedly just blanket intercepted all links and unknown-to-their-customers passed them through an HTTP redirect. Stunningly unprofessional.
- mholt 7y agoGood news for sure, but note that this isn't a total Internet scan: > We collect data from the browsers of site visitors to our exclusive on-demand network of analytics and social bookmarking products. More details about their samples: https://netmarketshare.com/methodology https://netmarketshare.com/methodology I would be more inclined to trust sources like https://transparencyreport.google.com/https/overview https://transparencyreport.google.com/https/overview and Firefox Telemetry which come directly from the browsers. But even these do not count data from mobile apps (most of which have to be encrypted now I think), embedded applications, scripts, and APIs.
- input_sh 7y ago> from mobile apps (most of which have to be encrypted now I think) Since the end of 2016 on iOS and since Android v9, apps have to communicate over HTTPS. I guess you can technically visit HTTP sites via a browser, but I'd bet that >90% of the traffic from smartphones is over HTTPS.
- nidificate 7y agoDo iOS or Android have any requirements vis a vis HSTS or HPKP?
- pvtmert 7y agobanking apps require them anyway (because of pci-dss etc)
- UncleMeat 7y ago> since Android v9, apps have to communicate over HTTPS That isn't true. It is the default but Android lets you override the defaults and use unencrypted traffic both in WebViews and in networking APIs.
- jsjohnst 7y agoIt’s not true in iOS either. It’s possible for an app to whitelist specific domains.
- vbezhenar 7y agoI wonder how many fuel is burned to power servers and browsers to constantly encrypt and decrypt data which could be transferred much more efficiently unencrypted.
- behringer 7y agoBy encrypting all traffic, you protect sensitive traffic better because an adversary can't tell sensitive from non-sensitive communications.
- iooi 7y agoI wonder how much metal is spent making door locks. Eh, probably better leaving all doors unlocked. I wonder how much steel is in a banks safe. Eh, better leave the safe open. I wonder how much time people spend typing in their passwords. Eh, better remove passwords from all sites.
- brojonat 7y agoI agree it's absurd to use this as an argument against encryption, but I am curious about what the number is. How much could a banana cost Michael, $10?
- jacquesm 7y agoEfficiency is overrated. Encryption stops injection or modification of data in flight in its tracks, that alone makes it worth it. Otherwise, how would you know you receive what the sender sent you?
- brlewis 7y agoI bet if you stress test a server via http and via https, the CPU time won't be as different as you might think. The main efficiency lost is that you can no longer have big shared cache networks for everybody, but those were a security risk anyway.
- basilgohar 7y agoThe somewhat surprising main problem is not CPU load but the additional back-and-forth TLS requires to establish the handshakes. One of the main goals/draws of HTTPS/3 is eliminating these extra steps.
- Jonnax 7y agoNice. Remember the days when IT professionals would exclaim that this was a bad idea? Seems like it's cyclical thing. DNS over HTTPS is now the big bad technology.
- aesh2Xa1 7y agoNo, haha. When was that a thing?
- smhenderson 7y agoI can't find anything specific at the moment but anecdotally I remember seeing this and being told it hurt performance to encrypt everything. The "solution" was to only encrypt sensitive pages like forms for credit cards. I'm sure there was some substance to it at the time when computers, networks and browsers were slower but I also completely ignored that advice at the time and always used SSL everywhere on sites I set up. I've never manged a very high traffic site so any extra overhead from SSL was negligible for us.
- mdavidn 7y agoWhen people were concerned about HTTPS overhead? Both in terms of increased latency when establishing a connection and AES overhead for the duration of the connection. Hardware TLS accelerators used to be a thing.
- jchw 7y agoIn the early 2000s almost any traffic that wasn’t involving financial services or ecommerce was plain HTTP. Gradually, HTTPS became optional (remember encrypted.google.com?) and more sites used it for login (but not all pages, even with cookies.) This meant that MITMs were a lot more effective. Hell, even today Comcast and some other ISPs will MITM you to send notifications when it can do so on a plaintext HTTP connection. A lot of IT departments also used this to be able to block unwanted traffic and perform monitoring. Now a lot of that relies on DPI techniques like analyzing SNI, or intercepting DNS. DoH and encrypted SNI work together to close both gaps, and widespread deployment of them would largely kill the ability to MITM or monitor consumer devices without modifications. In modern times the cost of TLS certificates and the overhead of TLS encryption has dropped to effectively zero, so that ship has sailed, and nobody even remembers there was any concern to begin with. Maybe this time, it will be different, due to the lack of other options for MITM. I imagine in the future there will be similar concerns about protocols that encrypt session layer bits like CurveCP.
- akerro 7y agoThanks NSA
- jancsika 7y agoTo the 90%: if you've got nothing to hide then why are you encrypting your traffic?
- ravenstine 7y agoComcast.
- philg_jr 7y agoProbably sarcasm but...why shut the door when you're in the bathroom?
- judge2020 7y agoOr "why lock your car doors when stealing and hotwiring is a crime"? Sure, people have convertibles and jeeps with no doors, but they also won't leave anything valuable out in the open.
- catalogia 7y agoI like this analogy. We all know what goes on inside a bathroom, it's not really a secret. But it is private. There is a difference between secrecy and privacy, and this analogy captures the difference well. I think I first heard the analogy in Cory Doctorow's presentation The Coming Civil War over General-purpose Computing, which was ironically given at Google. I highly recommend people watch it.
- p98uihser 7y agoBecause I can't connect directly to news.ycombinator.com, my request is first proxied through verizon and comcast and others. Without HTTPS it is super easy for them (or lesser known snooper) to add malware or whatever they want to the messages. It's useful because of the data integrity verification, not the encryption.
- paulddraper 7y agoSorry about the downvotes. Poe's law is a bitch.
- 7y ago
- lowiqprogrammer 7y agoThis is awesome, just 5 years ago the numbers were reversed.
- smolder 7y agoThat's good. One structural issue with the internet down, many more to go. There is essentially no guarantee that cloud providers don't snoop through memory and steal your keys and sift through your data, for instance. There are just some big companies that we implicitly trust. Whenever the endpoint for encryption /decryption is under the control of a 3rd party, any guarantee of data safety isn't real. We have devices that constantly go out looking for new code to run, with proprietary blobs in firmware, which means they're 3rd party controllable. Control of the internet is in the hands of organizations that can't be held accountable for abuse of power over individuals. I guess I'm just saying I don't have faith that a system (I'm talking about the intersection of technology, government, and business here) which puts so little power in the hands of individuals will do an adequate job of serving their interests in the long term.
- ga-vu 7y agoIt's been at over 90% for more than a month, from what I can tell
- gator-io 7y agoif you look at the trendline, it was 88.7% last month: https://netmarketshare.com/report.aspx?options=%7B%22filter%22%3A%7B%7D%2C%22dateLabel%22%3A%22Trend%22%2C%22attributes%22%3A%22share%22%2C%22group%22%3A%22secure%22%2C%22sort%22%3A%7B%22share%22%3A-1%7D%2C%22id%22%3A%22https%22%2C%22dateInterval%22%3A%22Monthly%22%2C%22dateStart%22%3A%222018-11%22%2C%22dateEnd%22%3A%222019-10%22%2C%22segments%22%3A%22-1000%22%7D https://netmarketshare.com/report.aspx?options=%7B%22filter%...
- alpb 7y agoAlso likely because in the past the internet was really diverse. One would visit 20 sites possibly during one session. Today, the landscape looks more like: You visit Google, click some links that open in AMP (still Google), visit some social networks (primarily Twitter and FB-owned properties). These companies already operate TLS-only, which helps these numbers.
- rb808 7y agoDoes this include Netflix traffic? Which would skew the results.
- campuscodi 7y agoNo, it didn't. NetMarketShare has a very limited view into these things. Actual data from browser makers Firefox - 80% https://letsencrypt.org/stats/ https://letsencrypt.org/stats/ Google -- 88% on Android; 84% on Windows; 91% on Mac; 73% on Linux https://transparencyreport.google.com/https/overview?hl=en https://transparencyreport.google.com/https/overview?hl=en
- est31 7y agoWhile this milestone is wonderful, don't forget that it can't be decrypted for now. IMO we trust contemporary encryption algorithms too much, putting too much data through the wires that will only increase in value. We aren't at the end of the evolution either: we still don't have really secure random generators everywhere, we are still using key exchange methods that aren't quantum proof. And of course, computer programs (as well as hardware) still have security bugs.
- tantalor 7y agoEncryption is worthless without properly enforcing it. How easy is it to trick your victim's bank into granting you access with a SIM swap? We need 2FA everywhere and stop relying on SMS for authentication.
- acid__ 7y agoI agree that we need 2FA and that we shouldn't rely on SMS. That said, saying encryption is worthless because other threat vectors exist is a bit hyperbolic. Security is all about defense in layers. There's several orders of magnitude difference in the difficulty of performing a SIM swap attack vs sucking up passwords on coffee shop wifi.
- edm0nd 7y agoAll banks should adopt U2F and hopefully sooner than later :)
- exolymph 7y agoIt's not worthless. It shrinks the attack surface and makes attacks more costly to execute. There's always an arms race though :P
- gambler 7y agoI don't know why so many people here are patting themselves on the back over this. This is not the kind of encryption people were talking about in the 90s and 00s. A lot of this encryption is not point-to-point. It merely secures user's interaction with some middleman (or their server). What would the numbers be if you subtracted all the traffic that can be snooped on by Google, Amazon and Cloudflare?
- paxys 7y agoThe encryption is still point-to-point, just that the website you are connecting to has chosen to make their "point" AWS or Cloudflare or whatever else. You could as easily host something in your own DC or from a machine under your desk.
- stjohnswarts 7y agoWhat are you talking about about? I think you better look up how https/tls works??? Sure you have to trust the certificate authority. Also can you imagine the scandal that would erupt if Google or AWS cloud was discovered to be eavesdropping on companies running things in their cloud? I don't think so.
- megous 7y agoThe point is that if you're communicating with someone via Google, encryption terminates at Google, not with the other party.
- gpm 7y ago> can you imagine the scandal that would erupt if Google or AWS cloud was discovered to be eavesdropping on companies running things in their cloud Remember the "SSL added and removed here" image? https://thumbs.mic.com/MTBjNTQzNTMzZiMvbWVtejZOdjJsaUdUVkZEa3I1cVgyVkRjTlFFPS8weDQwOjQ5MXgzNDkvODAweDQ1MC9maWx0ZXJzOmZvcm1hdChqcGVnKTpxdWFsaXR5KDgwKS9odHRwczovL3MzLmFtYXpvbmF3cy5jb20vcG9saWN5bWljLWltYWdlcy9kMjg1N2Q0MzliNGEwMDcyNmQwMzYwMGVjMTEzMzdkMjA2MDE4MWM2OTIzYjliN2NmYzc5ZGIyMjkxNDMwOWY0LmpwZw.jpg https://thumbs.mic.com/MTBjNTQzNTMzZiMvbWVtejZOdjJsaUdUVkZEa...
- jjice 7y agoI actually just set up SSL on my EC2 instance after reading this comment section. It was stupid easy, and I can't believe I didn't do it before
- svara 7y agoWe often hear the complaint here that nobody cares / cared about Snowden's revelations. But to me it seems he did provide a lot of the impetus for having HTTPS virtually everywhere and a lot of the instant messenging apps being end-to-end encrypted. Most of WhatsApp's users are as non-technical as it gets, and yet they use the kind of encryption that only computer enthusiasts were interested in just a couple years ago. It's a great development (all the limitations and caveats notwithstanding) IMO.
- newguy1234 7y agoAgree Snowden is significant because he was able to encourage enough people to INSIST on strong privacy/encryption. Then it all comes down to basic game theory. Why would a company ever want to release any product without strong encryption (end-to-end) when users never complain about their data being encrypted. The only reason companies don't encrypt is when they have a vested interest in spying, either in their own interest or the government's interest. Anytime I see something not have strong encryption, it is a red flag to me that something nefarious is up.
- loktarogar 7y agoEncryption in the last decade has also become a hell of a lot easier to implement, so "why wouldn't we just do it" has less opposition
- ethbro 7y agoI think this is underappreciated. High-quality crypto libraries / systems lead to broader implementation, which makes it harder for elements in mostly-free societies to pressure implementers. It's one thing for the NSA to quietly lean on ATT (and only ATT). It's a completely different thing for them to quietly lean on 1,000 different organizations and authors. Similarly, it's easy to sneak a CALEA-alike amendment into national law when only PGP exists. It's harder when the narrative becomes "The government wants to take {beloved product used by millions} away."
- shadowgovt 7y ago
- frankzen 7y agoThe Federal Government may not like this but this is heading to as it should be. Sometimes the government needs to be saved from itself!
- stjohnswarts 7y agoI would say there is a 50/50 chance that the government has access to any http certificates that it needs to crack any https session that they would like to crack. The Patriot Act created secret courts to enable this type of stuff. They're well known to rubber stamp any warrant that comes through.
- alexis_fr 7y agoAnd it is not unimaginable that the US government can crack the RSA. That would explain why they are not requiring people to use short keys, yet still collect the data worldwide.
- codexon 7y agoGovernments can force CAs to give them certs. HTTPS only stops non-government attackers.
- profmonocle 7y agoThey would be killing the CA by doing this, since all certs have to be publicly logged in order to be trusted by Chrome or Safari: https://en.wikipedia.org/wiki/Certificate_Transparency https://en.wikipedia.org/wiki/Certificate_Transparency If a minor CA suddenly issued a cert for, say, mail.google.com, they'd be distrusted by every browser/OS within days. If a government made a habit of doing this, there'd soon be no trusted CAs in their jurisdiction. The US probably has the best chance of getting away with this since they also have all the major OS/browser vendors in their jurisdiction. But if Mozilla/Apple/Microsoft/Google all mysteriously decided not to distrust a CA that was issuing bogus certs for high-profile sites, it would be pretty conspicuous.
- advisedwang 7y ago
- qrbLPHiKpiux 7y agoWho cares. Metadata reveals way more, anyway.
- whydoyoucare 7y agoThis statement would be more meaningful had it been phrased something like this: "encrypted web traffic, which most adversaries cannot snoop on, exceeds 90%". There will always be an adversary, far powerful than you, with an ability to snoop on your traffic - be it your ISP, the other endpoint, or owners of the infrastructure that you consume, but do not control.
- gnode 7y agoYou portray encryption as a magical energy. To the best understanding of cryptanalysis research, current TLS is secure. Hypothetically it could be broken and publicly unknown, but this is not a matter of "power". > the other endpoint It's not sensible to say encrypted web traffic is snooped on by an actor with direct access to the plaintext.
- whydoyoucare 7y agoThe simple statement made in OP, does not capture the complexity of operational security, which is very difficult to get right. I was merely trying to illustrate that. For e.g., even though TLS is end-to-end secure (and I don't doubt that), a website that uses CloudFlare front [1] is susecptible to its secure traffic being intercepted by CloudFlare, because by-design TLS would be terminated at CloudFlare servers'. However, note that the end-user does not notice that, rather he sees his traffic end-to-end encrypted. [1] https://support.cloudflare.com/hc/en-us/articles/200170416-End-to-end-HTTPS-with-Cloudflare-Part-3-SSL-options https://support.cloudflare.com/hc/en-us/articles/200170416-E...
- profmonocle 7y ago> a website that uses CloudFlare front [1] is susceptible to its secure traffic being intercepted by CloudFlare, because by-design TLS would be terminated at CloudFlare servers Keep in mind, this is also true of cloud providers. By running the hypervisor, AWS has full access to your instance's RAM and could snoop on traffic if they pleased. A compromised service provider is a risk you're accepting unless you own and physically control the hardware terminating TLS. Whether this is an acceptable risk comes down to your threat model. (As do so many things in infosec.)
- vinayan3 7y agoWe do need HTTP because sometimes public WiFi networks need you to agree to terms before any requests stop being redirected. I recently found http://neverssl.com http://neverssl.com That being said those public WiFi’s shouldn’t be redirecting sites in the first place because for HTTPs sites browsers don’t even let you see the page.
- vertex-four 7y agoThere's things like detectportal.firefox.com, which is used by Firefox to detect whether a captive portal is in effect.
- mahesh_rm 7y agohttp://http.rip http://http.rip
- MayeulC 7y agoI personally prefer http://example.com http://example.com as is it is explicitly http-only, adminitred by IANA. It boggles my mind that we haven't yet agreed on a signaling mechanism at the AP level (DHCP?) for signaling captive portals, as this seems to be quite a common use-case.
- CommentSections 7y agoSeeing is Believing; ~Far Seer: Warcraft;
- ksenzee 7y agoI wonder how much of this is due to Cory Doctorow's novel Little Brother.
- hamilcaraesop 7y agoInteresting read. This just peaked my interest in encrypted network
- meche123 7y agoOh, so finally most of the porn sites are defaulting to https?
- uxp100 7y agoI know this is good and all, but it does bum me out that Netscape 4.8 works much worse than it did even a few years ago. I prefer it to iCab, which might fair slightly better. Any suggestions for Mac OS 7.6 web browsers that support the minimum encryption required these days?
- bbanyc 7y agoMy suggestion is to set up a proxy. This has long been necessary to run browsers like Mosaic on the modern web, since many websites are inaccessible from HTTP/1.0 (or earlier!) It's funny how ever-moving Internet standards mean an Apple II from 40 years ago is more functional than an iMac from 20 years ago.
- ecesena 7y agoOne thing we recently started looking at is outbound traffic, i.e. links that people click within our website/app. We're going to publish some results (and joint forces) soon, but I wanted to share here because I feel outbound links are something usually ignored. Yet they can contribute to a significant part of the total Internet traffic. So, upgrading outbound links from http to https (where possible) can be another way to contribute to achieving 100% of the web traffic encrypted.
- gscott 7y agoThis is good to keep out moderate bad guys from your data. But the not so much for the NSA. The NSA already captures traffic end to end including the key negotiation and can break the rest https://arstechnica.com/information-technology/2015/10/how-the-nsa-can-break-trillions-of-encrypted-web-and-vpn-connections/ https://arstechnica.com/information-technology/2015/10/how-t...
- birdyrooster 7y agoThat was for 1024-bit SSL keys with specific primes, going to 2048-bit will not scale with $11B
- philipkglass 7y agoEven when it was first discovered, only 8.4% of the top million web sites were estimated to be vulnerable to the Logjam attack: https://arstechnica.com/information-technology/2015/05/https-crippling-attack-threatens-tens-of-thousands-of-web-and-mail-servers/ https://arstechnica.com/information-technology/2015/05/https... Now I would expect the number to be much closer to 0%.
- throw7 7y agoSo what. NSL.
- miguelmota 7y agoThis doesn't mean 90% of all websites. This simply means 90% of web traffic which I'm assuming a good chunk of it comes from a few handful of services such as Netflix and YouTube
- dr-detroit 7y agomost of the traffic is people watching people play videogames
- fuckface123 7y agoBut what does netcraft say?
- geometricstripe 7y agoThe trend is going in the right direction.
- santojleo 7y agoI’m sorry, but there’s a lot of smart people here. Why is everyone assuming HTTPS means no one is snooping? I presume someone is snooping no matter what.
- lrem 7y agoSnooping on Https requires significant resources. Snooping on http is very cheap. A good analogy is locking your door. Sure, can be dealt with. But most would be criminals won't go further than twisting the door knob.
- stefantalpalaru 7y agoAnd how much of it is being decrypted by Cloudflare?
- axaxs 7y agoGreat. Now nobody can see what you do except companies who sell everything you do...
- robbya 7y agoThe 50-50 point appears to have only been June 2017, so the cutover rate is really quite rapid. I wonder how quickly we'll see 95%, 99%, and how long the long tail will be. https://netmarketshare.com/report.aspx?options=%7B%22filter%22%3A%7B%7D%2C%22dateLabel%22%3A%22Custom%22%2C%22attributes%22%3A%22share%22%2C%22group%22%3A%22secure%22%2C%22sort%22%3A%7B%22share%22%3A-1%7D%2C%22id%22%3A%22https%22%2C%22dateInterval%22%3A%22Monthly%22%2C%22dateStart%22%3A%222017-05%22%2C%22dateEnd%22%3A%222017-06%22%2C%22hiddenSeries%22%3A%7B%7D%2C%22segments%22%3A%22-1000%22%7D https://netmarketshare.com/report.aspx?options=%7B%22filter%...
- ganitarashid 7y agoThank you Edward Snowden
- ourcat 7y agoThank you LetsEncrypt.
- jyutin 7y agogreate!
- spurgu 7y ago>If there was a machine that provided a written transcript of what someone did in the bathroom with no video/audio I don’t think people would mind. What if you're prone to release huge turds that often clog the toilets?
- code4tee 7y agoExcellent progress and a great credit to LetsEncrypt and others that brought free cents to the masses. There’s almost no excuse to not encrypt anymore. The “not secure” shaming of non https sites by major browsers also applied some needed peer pressure.