5 ms·
Why would it need encryption? The only convincing argument would be stuff like as insertions by ISPs and so on but that's extremely uncommon. Additionally every
by mburee 5y ago
Why would it need encryption? The only convincing argument would be stuff like as insertions by ISPs and so on but that's extremely uncommon. Additionally everyone and their mother seems to be a CA these days...
- beebmam 5y agoThere's more to HTTPS than just data integrity promises. One of the most popular topics on Hacker News is privacy, so I'd imagine people here would understand why virtually all public websites should be HTTPS only.
- qsort 5y agoAh yes, the obvious privacy implications of reading topics in elementary computer science. You are right that virtually all public websites should be HTTPS only. Serving static, non-sensitive data is the use case that "virtually" is there for.
- beebmam 5y agoIs there any reason to be so sarcastic here, other your desire to engage in bad faith here? There are good reasons to make the paths that people request on public websites private to the client & server, even when that content is seemingly not interesting (to you) to gather for snooping purposes.
- NikolaeVarius 5y agoIts always entertaining to see users claiming bad faith when they are engaging in bad faith themselves. Please list the good reasons that are relevant for a fully publically accessible page of information that contains nothing that asks for usernames/passwords or whatever.
- 533474 5y agoDon't feed the troll
- beebmam 5y agoThe proof of the burden as to why this website should force all communication to be public is on you. HTTPS exists and configuring it is simple in this era, and the choice to not use it for a university's public website is either laziness or incompetence. You surely must be aware that content like headers and even URL paths (and other parts of the URL) are confidential over HTTPS. Why should I allow an employer, an abusive spouse, an abusive parent, a parole officer, a detective looking to charge me with a crime, a gang looking to intimidate me, know which content I'm accessing from a website? All it takes is something like a wireshark application somewhere between (inclusive) my network and the server's network, and they will full have access to everything I've requested from the server and everything it has responded with, including all metadata. No warrants needed. Like I said in another comment: "Why should we make any personal details about our lives public information if it doesn't need to be? Do you go around announcing all the things that you do in your life that are seemingly harmless? Sometimes revealing information to the public that one would think is harmless can end up doing a lot of harm, both to you and others. Privacy matters, a lot."
- jcelerier 5y ago> Do you go around announcing all the things that you do in your life that are seemingly harmless? you must not like twitter much
- deleted 5y ago[deleted]
- Supermancho 5y ago> You are right that virtually all public websites should be HTTPS only. That is correct.
- theWreckluse 5y agoWhy’s it /so/ disappointing? I/We would definitely appreciate if you could elaborate. I’m not saying https is pointless, but why is it such a big deal for a site like this? And how is self signed better? If anything I’d say it’s worse! It creates a false sense of security.
- beebmam 5y agoSure I'd be glad to elaborate. Why should we make any personal details about our lives public information if it doesn't need to be? Do you go around announcing all the things that you do in your life that are seemingly harmless? Sometimes revealing information to the public that one would think is harmless can end up doing a lot of harm, both to you and others. Privacy matters, a lot. A self-signed certificate used for HTTPS still protects the client/server from snooping by a unaffiliated party, even if it doesn't protect from a MITM intercepting and responding to the request in the case where the client hasn't already added this self-signed certificate to their trusted CA store.
- utopcell 5y agoGoing against my better judgement and feeding the troll: While public key cryptography is Computer Science, HTTPS most definitely has nothing to do with Computer Science theory.
- cweagans 5y agoThere are many rationales already written in many places. https://https.cio.gov/everything/ https://https.cio.gov/everything/ for instance. Or https://doesmysiteneedhttps.com/ https://doesmysiteneedhttps.com/ .