5 ms·
>HTTPS adoption is now very high[1] I posted this in a separate comment and I will post it again. https://certbot.eff.org/hosting_providers https://certbot.ef
by colllectorof 6y ago
>HTTPS adoption is now very high[1]
I posted this in a separate comment and I will post it again.
https://certbot.eff.org/hosting_providers https://certbot.eff.org/hosting_providers
HTTPS adoption is hard enough that the wast majority of shared hosting providers haven't automated cert provisioning and are delegating this process to their users.
The push towards forced HTTPS has significant costs, which most people in this filter bubble don't want to honestly discuss.
- NeutronStar 6y agoOver 2/3rd of that list was last audited in 2019. A lot can change in 2 years.
- jopsen 6y agoAnd most them are probably holding back because they want customers to pay for an SSL certificate.
- silvestrov 6y agoThis filter bubble are of the very sensible conviction that those hosting providers then need to get their act together or go out of business. HTTPS is old tech. "Let's Encrypt" is free.
- sharedhostvet 6y agoI can tell you from personal experience that they are in the process of going out of business. Traditional shared hosts got their lunch eaten starting almost a decade ago with a combination of site builders like Weebly on the user friendly side and AWS on the technical side. In 2013 most of my social group was friends I made in the shared hosting industry. Now I don't know a single person still working for any MSP as they've all needed to find greener pastures as the companies get bought up by conglomerate vampires that will milk the remaining customers (there aren't many new ones) for what they're worth until the companies finally die. Looking to shared web hosts for guidance is like looking to 2005 to decide what's cutting edge. They're done for. Shared hosting is over. RIP cPanel, Plesk, and the whole lot
- Sanzig 6y agoAnd for technical users who find AWS/GCP/Azure and friends too expensive for whatever reason, there's enough small bargain basement VPS providers around that still beat the prices of the shared hosting providers while providing way more flexibility. I run my personal blog using a mom-and-pop KVM VPS provider that costs $2 per month, and I get full control over whatever stack I want to run. Shared hosting is awful, I don't know why anyone would ever want to go back. Here's an Apache server we set up, it's got every module under the sun enabled along with the associated security holes. You get one PHP version that we upgrade at our leisure, and a shared MySQL server that you pay per database for. Eugh.
- jopsen 6y ago> Shared hosting is awful, Actually, I've come to respect it as an offering because I don't need to patch security vulnerabilities. I don't need to do backup, etc. If/when I do eventually migrate to a VPS I'll be responsible for a LOT more. I'm tempted to move to a PaaS or go serverless, but cost management with serverless is more complicated. My dreamhost setup has been going fine for almost a decade by now. With minimal maintenance from me.
- laurent92 6y agoDigitalOcean at $5 is a very good deal too. And one can keep evolving with DO, implementing private networks or using hosted DB.
- tgsovlerkhgsel 6y ago> Shared hosting is awful Depends on your use case. For my use case, I upload a bunch of HTML files via SFTP, and it just keeps working. I don't have to deal with the server software, someone who can dedicate a lot more time does that for me for a nominal cost (because keeping the server for 10000 people updated is only marginally more difficult than me keeping my own server updated). I pay the same or less than I'd pay for a small server, and someone who provides the benefit of a managed platform gets some profit for the value (hassle free website) they created. In exchange, I save an hour or two of fiddling with the server per year, which makes this a great deal. You're not paying for infrastructure, you're paying for the "managed" part of a managed service. Could I just use a storage bucket? Probably. But I'd have to figure out how to make Let's Encrypt work with that, and if someone decides they hate me and downloads my site with a million bots several times per second, I'm getting a bill that costs me more than a lifetime of shared hosting. If I were to use PHP and MySQL... they'd probably still update it more diligently than I would after a year when I get busy with other things.
- morpheuskafka 6y agoIf you aren't technical enough to manage provisioning yourself, or don't want to, you are most likely throwing the site behind Cloudflare which automagically terminates TLS for free, or paying for some other CDN that does the same. Or if you really aren't technical at all, you would be using Wordpress.com or a similar platform that takes care of it for you. Actually, I have seen several domain registrars that want to advertise "free SSL" implementing some sort of basic Let's Encrypt provisioning tool that automatically updates the TXT records to get them.
- danShumway 6y ago> The push towards forced HTTPS has significant costs, which most people in this filter bubble don't want to honestly discuss. I agree, but I'll push back by saying that delaying HTTPS adoption and getting lax about it has a much higher cost -- and that is similarly a cost that most people pushing back against HTTPS either downplay or refuse to acknowledge. And more than that, those critics have shown that they're not interested in solving the problems that they bring up or in finding ways to mitigate them. So it's not like we can wait a year and adoption will suddenly get easier. The critics of HTTPS aren't moving forward. They don't want HTTPS adoption to slow down while they catch up, they want it to stop so that they don't need to move forward at all. We've seen significant improvements in usability for HTTPS for ordinary people, from LetsEncrypt, to Cloudflare, to Netlify. Holdouts like Gitlab and Github don't provide an easy way to provision certs by default. A lot of other smaller hosting providers are ignoring the problem entirely. This will get better over time as more hosting providers realize that this is a feature they have to provide to be competitive. But that's the thing. Smaller hosts are ignoring the problem and they will continue to ignore the problem until they're forced to upgrade their infrastructure to support solutions like Certbot. Because MITM attacks aren't their problem, client privacy isn't their problem. They are not going to get better support until they literally don't have any other option. That changes our calculations; where a decade or two ago we might honestly argue that immediate, harsh incentives to switch to HTTPS had too many downsides, we're now in a position where we realize that harsh incentives are the only way that HTTPS infrastructure is going to improve at all. And that has significant implications for people's privacy and security online. We're at the point where even though it's a barrier of entry for some people, everyone should still be using HTTPS on any public site that they build, period. Honestly, I'm in the process of trying to find good HTTPS schemes for intranet sites too. We need to move forward on security.
- sumtechguy 6y agoTo add to that https I think is one part of the puzzle. This weekend I watched a bunch of scam bait calls. Very amusing to watch them get taken down. But there are people out there mailing 20k in fedex boxes to scammers. All because their browser said 'your balance is 20000 and I transferred too much to the account, could you mail that back to me so I do not get in trouble?'. It is a very human attack using a combination manipulation, fear and compassion. The bottom line is these people unknowingly allowed people to open the debug console in their browser to change things. What I have been trying to figure out in my head is how do we do a digital watermark on data presented to the user? How do we at a minimum tell the user their data has been manipulated? You can have all the TLS on every level but at one of the most important ones there is nothing. A scammer can open a debug console on a https presented page just as much as a http page.
- tgsovlerkhgsel 6y agoThe solution to that is to find a more competent hosting provider.