5 ms·
I don't disagree with what you're saying, but I feel HTTPS everywhere does not belong in that list. Secure by default doesn't sound evil to me, and Let's Encryp
by deallocator 6y ago
I don't disagree with what you're saying, but I feel HTTPS everywhere does not belong in that list.
Secure by default doesn't sound evil to me, and Let's Encrypt made it easy enough to get free HTTPS certificates (and for non technical people, almost all hosting services I've seen offer it out of the box)
- varispeed 6y agoLet's Encrypt has de facto monopoly. I think we could have added HTTPS if we had dozens of projects like Let's Encrypt otherwise this is just handing over too much control to one organisation.
- madeofpalk 6y ago> Let's Encrypt has de facto monopoly. Is that even remotely true? There are alternatives to Lets Encrypt - AWS has an equivalent project where they issue free SSL certs for AWS resources.
- hhjj 6y agoIf it is for AWS resources it is not equivalent.
- solarengineer 6y agoAWS don’t owe non AWS customers free certificates, though. It is possible to host LetsEncrypt alternatives, though. The viability is another matter, though.
- pessimizer 6y agoLetsEncrypt doesn't owe anyone free certificates, either. The point is that AWS isn't an alternative unless you're spending money with AWS. Nobody is wondering whether you can get a certificate by paying someone.
- madeofpalk 6y agoEquivalent in the sense that, if you're in AWS (which is a non-insignficant amount of people) then you have options other then Lets Encrypt.
- yjftsjthsd-h 6y agoAnd zerossl exists for non-aws
- Const-me 6y ago> Let's Encrypt made it easy enough to get free HTTPS certificates Just checked. My hosting provider asks 2x more money for SSL addon (which includes unique IP, unlimited subdomains, and free certificate). They wrote on the support forum I need that addon regardless on which certificate I gonna use, the included free one, or any other like lets encrypt. Not gonna switch hosting nor pay 2x more for it just to please Google.
- shermheadryder 6y ago> Not gonna switch hosting nor pay 2x more for it just to please Google. Let's not pretend that HTTPS only exists to please Google. It has very real benefits for your users.
- Const-me 6y agoMy web site has no comments or other user-generated content, runs no CMS, uses no cookies, collects no data except standard web server logs, hosts no executables, and has no secret nor security sensitive content.
- wepple 6y agoAt Starbucks I can inject arbitrary content into the browser of anyone who visits your site over HTTP and take control of their browser. Furthermore, congrats on your site but you’re 0.01% of sites like that. Should we keep an insecure web because your hosting provider is ripping you off? TLS is easy and free in 2021.
- BunsanSpace 6y agoA static blog that takes no user input/data doesn't need HTTPS. Here's a good lecture about why HTTPS everywhere isn't as important as people think. http://n-gate.com/software/2017/07/12/0/ http://n-gate.com/software/2017/07/12/0/
- pessimizer 6y agoA static blog that takes no user input/data will still leak the pages on that blog you visit, and the times you visited them. Knowing that you went to a particular page on a particular blog is a lot more information than knowing if you went to a domain. If I know you read about Conan the Barbarian on three different blogs, I know to send you ads about Conan the Barbarian (as a trivial example.)
- phantomathkg 6y agoPretty sure Troy Hunt have already mentioned why even a static blog should use HTTPS. https://www.troyhunt.com/heres-why-your-static-website-needs-https/ https://www.troyhunt.com/heres-why-your-static-website-needs...
- bogomipz 6y agoThat link does not load for me. The redirect to the the captcha is broken. Sincere question - is that the point? In other words Google blocks the captcha loading since the site isn't using HTTPS?
- jimmydorry 6y agoIn a perfect world, sure, static sites don't need HTTPs. However, ISPs and other malevolent middle-parties have demonstrated why HTTPS is a must. We've seen everything from injecting tracking javascript, to injecting their own ads, to outright replacing content with unrelated content that the ISP wants to push.
- bandie91 6y agoin a perfect world, we would not secure the transport but the content itself. and everyone should be able to build their own web-of-trust. why i as a (web-) publisher and my readers have to rely on the grace of just a few root CAs? i know technically it is possible to import my home-made CA cert in browsers, but it's not made easy: my server cert can not be signed by more than 1 parties; android requisites an unlock code in order to have custom CA certs - first when i saw this i was like "why the hell?", i mean i can imagine this is safety feature for simple users but come on!