12 ms·
Nice stuff. I love the idea of really learning electronics, but I find it very much beyond what I would need to build the things I want to build. PS. Guys HTTP
by DigitalNoumena 3y ago
Nice stuff. I love the idea of really learning electronics, but I find it very much beyond what I would need to build the things I want to build.
PS. Guys HTTPS please!
- gokhan 3y agoWhy do you need https for this site?
- aaron695 3y ago[dead]
- DigitalNoumena 3y agohttps://www.troyhunt.com/heres-why-your-static-website-needs-https/ https://www.troyhunt.com/heres-why-your-static-website-needs... The whole video is great, but particularly this: https://www.youtube.com/watch?v=_BNIkw4Ao9w&t=1063s https://www.youtube.com/watch?v=_BNIkw4Ao9w&t=1063s https://doesmysiteneedhttps.com/ https://doesmysiteneedhttps.com/ There are a lot of arguments about why, even non-secret data connections need encryption. The first and most obvious is that not doing so immediately puts a target on the encrypted data. By no means an expert but to me it seems like an oversight not to.
- chrisjj 3y agoAnd then there's the why not. E.g. https://www.zdnet.com/article/lets-encrypt-to-revoke-3-million-certificates-on-march-4-due-to-bug/ https://www.zdnet.com/article/lets-encrypt-to-revoke-3-milli...
- DigitalNoumena 3y agoSo what you're saying is: HTTPS is secure -> a bug made 2.6% of all certificates less secure -> that's why we shouldn't use HTTPS? I'm quite confused how that holds logically. You can either argue HTTPS is fundamentally not secure or is irrelevant; or regret that there was a bug but support using HTTPS
- chrisjj 3y agoSorry, I should have used this better example: https://www.google.com/amp/s/techcrunch.com/2021/09/21/lets-encrypt-root-expiry/amp/ https://www.google.com/amp/s/techcrunch.com/2021/09/21/lets-...
- DigitalNoumena 3y agoFair enough, that doesn't sound great. That being said: > Devices likely to be affected by the certificate expiry are those that don’t get updated regularly, like embedded systems that are designed not to automatically update or smartphones running years-old software releases. Users running older versions of macOS 2016 and Windows XP (with Service Pack 3) are likely to face issues, along with clients dependent on OpenSSL 1.0.2 or earlier, and older PlayStations that haven’t been upgraded to newer firmware. Still not convinced we can claim HTTPS should not be used in the general, or in this particular, case.
- chrisjj 3y agoIf priority is maximing viewability for this site, HTTP beats HTTPS.
- DigitalNoumena 3y agoWhy would that be the case? Every modern browser actively discourages visiting HTTP sites so I imagine a non-negligible amount of users decide not to visit the page.
- chrisjj 3y agoThat's a myth. E.g. latest Android Chrome here gives zero discouragement. As is proper.
- DigitalNoumena 3y agoHaha fair enough but I think we digress. I did get the warning when I clicked. The point is I see no evidence why HTTP is better for viewability than HTTPS. I showed there are cases where it’s not. You showed there are cases where it’s irrelevant. But the point remains… when is it worse and is it enough to sacrifice the security benefits?