6 ms·
I agree with the author's points entirely, but I'm going to be the devil's advocate here and argue that this is fine. Sure, old websites will stop working, but
by princekolt 6y ago
I agree with the author's points entirely, but I'm going to be the devil's advocate here and argue that this is fine.
Sure, old websites will stop working, but just as we shut down our FM radio and analog TV to make room for new amazing technology, and therefore rendered several generations of radio and TV devices useless, the internet will need to learn to live with the fact we can't possibly support its entire spectrum of functionality forever.
However, I see this as a tooling and ergonomics issue. Despite what people say about certbot, it is still not 100% trivial to use it. If your stack differs slightly from the canonical HTTPS server, you're gonna have issues. I'm not saying these problems are inherent to certbot, just that there is room for improvement.
Once we have normalized how certificates are signed and verified, and use encryption methods that can easily be tuned for increased computing power, and more importantly, once HTTP 1.0 is no longer an expectation, I believe the amount of manual work needed to maintain a server will go down again.
We're at a transition phase and we all know these are never easy (except if you're Apple and you're transitioning CPUs architectures, apparently).
- anthk 6y agoFM radio degraded well.
- holri 6y agoMy very, very old Telefunken FM Radio in my workshop full of dust and dirt works flawlessly. I tried to replace it with a modern, shiny one. But this new one broke after a few months. Now I placed the old one where it was for centuries and now it happily plays my favorite program again.
- sp332 6y agoAnalog TV had to be moved because it was taking up limited resources. Old websites aren't taking up valuable real estate. There's no benefit to shutting them down.
- crazygringo 6y agoOf course there is. If they're HTTP, they're insecure, which makes them an open attack vector. Modern computer security is about removing as many known possible attack vectors as possible. So that's the benefit. EDIT: to those saying browsers are sandboxed or that there's nothing sensitive, it projects against e.g. Comcast injecting JavaScript into pages from other sites. [1] There are all sorts of types of bad actors out there. Surely I don't need to list them all here. [1] https://thenextweb.com/insights/2017/12/11/comcast-continues-to-inject-its-own-code-into-websites-you-visit/ https://thenextweb.com/insights/2017/12/11/comcast-continues...
- sp332 6y agoThere's no point having a web browser that doesn't browse just because it's more secure that way! Browsers have never had better sandboxes. Firefox disables certain features for sites served via plain HTTP. It's safer now to browse unencrypted sites than it was five years ago. There's no reason to remove functionality now.
- bow_ 6y agoHere I disagree. HTTPS gives guarantee to visitors of the site that they can trust the information being served to them. A malicious actor hijacking plain HTTP connections does not necessarily have to inject code that harms the user's computer directly. He/she could also just alter bits and pieces of the served content to trick the user into doing something not in his/her interest. So while having better browser sandboxing and protection is good (and welcome), HTTPS is still necessary.
- ComputerGuru 6y agoOld and unmaintained websites are not collecting any information, let alone sensitive information. They’re mainly read-only, informative content that the web would be infinitely worse-off without.
- JoshTriplett 6y agoThe Internet Archive helps maintain that information far more reliably than a 20-year-old unpatched webserver could.
- generalpass 6y agoIndeed. As I understand it, *BSD users are currently left out of wildcard certs from Let's Encrypt. HN runs behind an nginx proxy because the forum software doesn't support HTTPS.
- cpach 6y agoWhat is the issue with *BSD and LE wildcard certs? Would be interesting to hear more about that.
- generalpass 6y agohttps://certbot.eff.org/lets-encrypt/opbsd6-other https://certbot.eff.org/lets-encrypt/opbsd6-other
- cpach 6y agoCertbot is just one of many ACME clients. AFAICT acme.sh can do wildcard certs, and it’s not dependent on Bash. https://github.com/acmesh-official/acme.sh https://github.com/acmesh-official/acme.sh
- anthk 6y agoWhat? OpenBSD works just fine.
- hedora 6y agoThere are a few certbot clients for openbsd, at least. I’m using one that was written in bash with httpd, and I think they added a new one to the base image. Using the script was a bit annoying because I had to install bash from ports. As on my Linux and Synology machines, the bash script has broken once or twice because it’s against modern best practices to define and stick with stable protocols. Sometimes I think it would be easier to rewind to the 90’s web and build a sane ecosystem on top of that. Every aspect of the web that I interact with has gotten worse in the last decade. (Also, HN’s is using a non-wildcard cert from digicert, at least according to my web browser).
- joshspankit 6y agoSome old sites are valuable for archeology, some because they contain information that’s still true and not replicated anywhere else, some simply because they are interesting culturally. To say it’s ok to bail on all old sites is to say that it’s ok to bail on all old books. Someone put time and effort in to freely sharing these things for a reason, and it’s a loss for us all to throw it out in the name of “new”.
- princekolt 6y agoBooks, under normal conditions, will not decay by themselves either. However a librarian is still very much needed to preserve and organize them. The main issue is that HTTPS as it is developing right now is the antithesis of HTTP1. Everything that HTTP1 relies on is defines as bad by HTTPS. Either we change the direction of HTTPS or we drop HTTP. We can't have both. Of course, if the server is up and connected to the internet, it will always be accessible by browsers that can be configured to ignore the missing HTTPS features, as it is now. But as I said on a different comment we should not rely on this being here for much longer.
- joshspankit 6y agoDefinitely agree. I’m glad we’re having these discussions and that these points are being brought up.
- UncleMeat 6y agoThe problems with archiving the web are numerous but I find it frustrating when this argument is used without getting historians involved. It feels like people use the idea of archiving as a cudgel rather than actually supporting real work in this area.
- joshspankit 6y agoThough it seems counter to my argument, I agree with you. We need to stop using cudgels and just focus on the real work needed.
- gambler 6y agoReplacing FM radio is a huge societal mistake. Its simplicity enabled countless innovations that would and will not be possible with satellite radio. The technology (unlike analog TV) works perfectly fine for its core purpose and has numerous spinoffs (from radio clocks to OP-1 built-in radio sampler).
- stonogo 6y agoAnd as you sunset FM radio, you cut huge swaths of humanity out of yet another communications channel. FM radios are cheap, well-established technology, perfectly suited to mass communications (as in emergency alerts, etc). It survives suboptimal conditions (fuzzy broadcasts are still intelligible, receivers can be operated on hand-crank power, replacing equipment can be done at a dollar-store, etc). The amazing new technology that replaces it is without exception more complex, less reliable, and requires more infrastructure, and the associated costs invariable lock some segment of society out of participation. On the web side of this analogy, we're so fortunate to have people like Neocities trying to rebuild those bridges to the beginners, the resource-deprived, and the other edges of society, but with every crank of this ratchet we (literally!) excommunicate another set of our species, and that's depressing as hell.