4 ms·
~$5/year (US) for a domain, and a one time investment of setting up a few scripts might save you a lot of time in the long run.
by demersb 6y ago
~$5/year (US) for a domain, and a one time investment of setting up a few scripts might save you a lot of time in the long run.
- xg15 6y agoHonestly, my main issue is not even the price, it's that devices cannot be stand-alone anymore. Even if my device is purely for LAN use and wouldn't need the internet at all, I now need to ensure it has an internet connection and I have to keep a domain owned that must be constantly renewed. The device will also only be accessible if an internet connection is present, even if both the device and the client are in the same LAN - because the client has to access the device through the domain. This means, should I ever lose the capacity to support the device and renew the domain, the device will become useless, even if technically, it is still completely functional.
- gsich 6y agoNo. Your DNS can also be locally, so you have no Internet dependence.
- p2t2p 6y ago> Honestly, my main issue is not even the price, it's that devices cannot be stand-alone anymore. That’s not true at all. I’ve created a CA and a script to generate and sign server certificates and I generated them left right and centre now for my very standalone, local network only with no access to the internet whatsoever services. I added my CA to my browsers and my iPhone and everything works perfectly.
- xg15 6y agoWill you also add it to the iPhones of other people that would want to use the device? (Or more realistically, would they let you add it?)
- gsich 6y agoDepends on them I guess. If it's a corporate phone then it's no problem. The rest can either add it or get used to cert warnings.
- xg15 6y agoIf you're in a context where you can personally install it on phones of friends and relatives, that will work, I agree. I'm thinking of an example to illustrate what I mean. (Sorry if this appears to be moving the goalposts) Imagine some small business is selling a home surveillance camera, or a network printer or whatever else. The thing is that it's a product intended for perivate, layman consumers and intended for LAN use. With HTTP, you could add a local web server as a simple way to manage the device pretty easily: Just open a server, communicate the IP address to the user, done. No internet connection required, no continuing support from the company required. Even if the company went bust, the existing units continued to work and the web interface stayed accessible. There seems to be no good way to replicate this with HTTPS. The closest seems indeed to be a custom root CA - however, then you need to communicate to your users how to install the CA certificate on their own devices, clicking through all kinds of scary warnings and dismissing "this section is for admins only" notices. I predict that not a lot of people would do that. This also leaves you with the challange to safely get the certificate to your users. You could serve the certificate from the device over HTTP - however, then you'll require that your customers download a root certificate, over an unencrypted connection without any integrity checks and install it on their device. This seems like ripping open a mojor security hole. Meanwhile, even if the company purchases a domain and attempts to get a certificate from a public CA, deployment will be difficult as described in all the other branches of this thread. In short, I think you can pick any three of the following four conditions, but I see no way to archieve all four at the same time. (1) use modern web features (all recently added and all future features require https) (2) have your site usable on a client device that does not belong to you (3) present a non-confusing user experience (no cert warnings, etc) (4) have the device stay accessible even after you stop actively supporting it (by purchasing domains, running cloud services, having deals with CAs, etc etc)
- 6y ago
- hannob 6y ago> Honestly, my main issue is not even the price, it's that devices cannot be stand-alone anymore. I'm wondering where the impression fo" not any more" comes from. Really the situation hasn't changed much. You can have your HTTP webinterface. You can have HTTPS with a selfsigned cert and click away the warning. The only thing that really has changed is that for your HTTP connection you will get a warning that the connection is not secure. I don't think the ability of browsers to load HTTP pages will go away any time soon.
- nitrogen 6y agoAren't browsers preventing submission of form data over http now?