4 ms·
"There is no excuse for any public facing website with a fully-qualified domain name to not have encryption anymore." This is a display of arrogance and lack o
by dahwolf 3y ago
"There is no excuse for any public facing website with a fully-qualified domain name to not have encryption anymore."
This is a display of arrogance and lack of empathy matching the Chrome team's article.
There is a sizable "old web". Built by amateurs. Think people writing web pages in Microsoft Word and FTP-ing it. They're not web developers or sysadmins and have absolutely no idea what we're talking about when we insist they should just install certbot.
Many of the owners may not be reachable anymore or in the worst case, dead.
I object to breaking the old web. I object to the assumption that behind every website there is a competent tech team, perpetually upgrading whatever others decide to break from some ivory tower. And whilst I don't need convincing of the security benefits of HTTPs, I worry about the centralizing force that it is.
Take out Letsencrypt and Cloudflare and you destroy the internet. We're practically begging for it.
- hsbauauvhabzb 3y agoLinux distro repositories commonly use http and gpg verify on the host, as the repository hosting provider may be as grey party. I assume tls overhead on CDNs would be substantial, so if cryptographic verification can be offloaded elsewhere, maybe that is a reasonable solution in some cases.
- insanitybit 3y ago> I object to breaking the old web. Just click through the warning.
- superkuh 3y agoSure, as geeks we're all going to click though. But 99% of people aren't going to. So that makes hosting a visitable website pretty hard.
- insanitybit 3y agoI just think that's significantly different from "breaking" the old web. Nothing is broken.
- rurp 3y agoTotally agree. Old forums and personal websites are some of the best resources on the web for many topics outside of current events. Google Search already downranks them in favor of more corporate results, and this Chromium change will hurt that part of the web even more. It's maddening that so many people in tech seem oblivious to the fact that most people in the world interact with the web totally differently than them and have very different interests. Google in particular can be so hostile to people who couldn't care less about the latest tech trends and just want the stuff they care about to work with minimal fuss.
- kmeisthax 3y agoIf you're writing HTML directly and SFTPing into a server, you probably are also using a shared hosting platform that offers Lets Encrypt. You don't even need to touch a config file or install certbot in that case, you literally just click a button. If your host does not offer Lets Encrypt there are hundreds that will host bare files and do offer encryption, and migration is as simple as copy-pasting files and transferring the domain. If the owners are unreachable or dead you have bigger problems to worry about then having to click through to an unencrypted site. Dead people can't pay hosting bills. I get what you're saying with centralization but LE is not the only central point of failure here. The old web would not survive, say, VeriSign deciding to make .com worse or ICANN deciding to kill DNS. At least we can switch CAs.