4 ms·
Yeah, I empathize but he's really not reading current trends at all if he thinks HTTP is still going to be around in 3 years. I can't wait for the pure hell th
by krinchan 5y ago
Yeah, I empathize but he's really not reading current trends at all if he thinks HTTP is still going to be around in 3 years.
I can't wait for the pure hell that is captive WiFi once browsers provide sufficient friction to accessing non-HTTPS sites. Most devices are good enough at popping up the portal but far too often I find myself pulling up http://neverssl.com http://neverssl.com to force things to start working.
- yholio 5y agoIt's only a matter of time until captive WiFi networks will force you to install their root certificate or app if you want to use their services.
- EamonnMR 5y agoCaptive wifi is basically dead already, anyone who thinks they are providing a service by running it is mistaken. It's been busted due to https for years now. It's also almost always some sort of pointless CYA wifi license agreement.
- necovek 5y agoHaha, want to put a bet on those 3 years? :D HTTP is here to stay. Maybe browsers on PCs will make accessing it extra hard, though I suspect that's untrue as well (maybe POSTing data to HTTP web sites will be harder in that people will see extra pop-ups). But sites which have lived as HTTP forever are not going to magically get some maintenance done on them to move to HTTPS, and people will still visit those web sites. And let's talk about all those crazy cheapo IoT devices that are already spreading through the world that have their "http" servers hard-coded. Don't get me wrong, I've been on the HTTPS bandwagon since forever (before LetsEncrypt, the best deal you could get for multi-domain personal webpage certs was StartSSL, an Isreali company with very buggy software that you had to fight to get a cert issued). And I've long (decades?) advocated that browsers should first try an HTTPS page when protocol-less URL is given (which they are only now moving to, duh?).
- krinchan 5y agoAt some point, for everyday users, the amount of friction and bright red will just mean that they move on to another site. What popular site isn't using HTTPS? But I'm not even talking about desktop browsers, here. It'll start with mobile devices. iOS and Android going HTTPS only with their default browsers is entirely within the realm of reason. Flash was functionally dead once Android gave up on it within a few years. Yes, there was a long tail of enterprise users and people who refused to give it up. Similarly, there will be a very long tail of HTTP. But Apple and Google are in a position to kill it just like they did Flash.
- necovek 5y agoI am not so sure of the "everyday users": we are all conditioned to click through a bunch of "warnings" (cookie consent anyone?), that you'd really have to make it bordering on unusable for people to not simply click-through. Even with mobile devices, I imagine another cycle is coming where people care more about what their seemigly-general-purpose computers restrict them from doing. But I'd still wager that it ain't happening in the next 3 years.