4 ms·
Not a compelling argument in the least. MITM still means ISPs can track and inject ads, regardless of how static the content is on your website. And the perfo
by SquareWheel 4y ago
Not a compelling argument in the least. MITM still means ISPs can track and inject ads, regardless of how static the content is on your website. And the performance argument is completely invalid because it's only measuring total bytes, and doesn't consider HTTP/2 multiplexing.
> It should be mentioned that my personal website is also plain text based and tiny. Imagine the impact of a blog article or research paper with significantly more content.
The larger the website, the greater the improvement from using HTTP/2 (which requires TLS). And it doesn't take much data at all to offset that TLS lookup.
This post is justifying bad behavior. The only sites that can afford to remain http are neverssl.com and local development.
- soruly 4y agoeven for local development, I tend to serve the HTTP server with nginx for adding HTTPS. Because many of the web APIs, like service worker, clipboard APIs, are only available in HTTPS context.
- JamesSwift 4y agoUnfortunately mobile apps complain a ton about 'insecure' https, and make it a real chore to do local certs. So its usually easier to just run over http locally when doing mobile dev.