4 ms·
No HTTPS for this site? :-/
by brycewray 3y ago
No HTTPS for this site? :-/
- CharlesW 3y agohttp://scripting.com/2014/08/08/myBlogDoesntNeedHttps.html http://scripting.com/2014/08/08/myBlogDoesntNeedHttps.html
- brycewray 3y agoAh. Thanks, wasn’t aware. (In 2014, he might have had a tiny point --- but, now... Hmm.)
- jerf 3y agoIt's still not the easiest to come up with an attack of consequence against what is basically a static site that is worth an attacker's time. You can draw out scenarios, certainly, but most of them are some combination of "doesn't matter" and "if that's the goal, there's a better and easier way to do it". I ran on that philosophy for a long time too, but Let's Encrypt tipped the balance for me. When TLS certs cost real money it was easy to decide that the super-marginal security benefits for my minimal readers weren't worth hundreds of my dollars a year. Now it's more on the order of "incidental noise in what it took to set the website up anyhow", so I go for it.
- raspyberr 3y agoWhat would you have gained from reading the site in HTTPS?
- mcherm 3y agoConfidence that Verizon (my internet service provider) would not know what article I was reading (although they would still know what servers I was connecting to) and would not be selling that information to anyone.
- davewiner 3y agohttp://this.how/googleAndHttp http://this.how/googleAndHttp
- brycewray 3y agoYes, sir, later was directed by someone else to your opinion on this issue. I understand your points (while respectfully disagreeing). All that said, thanks for your wholehearted efforts over the years on behalf of RSS and all of us who still enjoy using it.