3 ms·
No offense, but an SSL certificate these days is a must, and not having one on your site is a big no-no. Sorry.
by KnowtheRopes 2y ago
No offense, but an SSL certificate these days is a must, and not having one on your site is a big no-no. Sorry.
- KnowtheRopes 2y agoI guess nobody cares this days about being safe and secure. :(
- bramblerose 2y agoWhich risk would TLS mitigate in this specific use case?
- ndsipa_pomu 2y agoAs with any http website, a malicious actor (e.g. someone in a coffee shop or an airport) could set up a plausible looking wifi service and then MITM the website and insert adverts or malware into the page. However, that has been discussed on many other topics that are directly to do with TLS/certificates etc. so I don't think it's worth bringing up (aimed at the OP) every time there's an HTTP linked.
- batch12 2y ago> I don't think it's worth bringing up (aimed at the OP) every time there's an HTTP linked. Maybe rewritten it could be viewed as a warning for those who care instead of a criticism.
- ndsipa_pomu 2y agoI'd rather just have the browser warn me
- lxgr 2y agoWith HTTPS, the site author could still do all of that, no? So I’m not convinced this is really that big of a concern on an unknown website that I’m not entering any credentials or personal information on.
- dingnuts 2y agothe SITE can do that when HTTPS is used, yes, but an unauthorized third party can inject stuff much more easily when it's plain HTTP. A little ARP poisoning and some mitmproxy and before you know it you're injecting malware or whatever Whether or not that matters when viewing this particular site is up for debate
- lxgr 2y agoYes – into the sandbox of this particular site (and limited to non-HTTPS-mandatory browser APIs at that). If that's a big threat vector, I feel like the much bigger risk would be visiting malicious sites, not a local or ISP located attacker injecting stuff into benevolent-but-HTTP-only ones.
- ndsipa_pomu 2y ago> limited to non-HTTPS-mandatory browser APIs at that Another trick that could easily be pulled by a malicious ISP/wifi provider is to insert a redirect into the HTTP page to go to an HTTPS site controlled by the attacker (presumably with some semi-related name so as to not seem suspicious to the user) and to then bypass non-HTTPS restrictions in the browser.
- ndsipa_pomu 2y agoThat's more of an issue with trusting any website, whereas TLS mitigates the risk of trusting a wifi provider or ISP. I also don't think it's much of a concern for old, infrequently used sites, but I wouldn't trust the competence of a modern website that didn't have a current SSL cert.
- yjftsjthsd-h 2y agohttps://doesmysiteneedhttps.com/ https://doesmysiteneedhttps.com/
- freedomben 2y agoIt would be amazing if that site were served only over http
- yjftsjthsd-h 2y agoAlternatively in the same vein, I wonder if it's possible to make a web server only listen on 443. I feel like maybe modern browsers try that first so you can skip 80 and it works?
- lxgr 2y agoFor new pages, sure, but this is a post from 2006. The author is likely not updating it anymore, so you are effectively complaining to a group of people here that can do absolutely nothing about it.
- KomoD 2y agoIt's a blog from 2006-2010, I'm happy it's up at all.
- Mistletoe 2y agoIs Ken Johnson still alive? I’m curious about how the blog is still up and why a programming type wouldn’t fix the encoding errors.
- henriquecm8 2y agoI don't know if it's the same Ken Johnson, but I found a video about AppSec with a Ken Johnson that had his twitter profile in the description https://x.com/cktricky https://x.com/cktricky. Then I found this Ken Johnson LinkedIn page, and there's no mention of working at Microsoft, so it's probably not the same guy, and this other Ken Johnson looks much younger than I was expecting.
- Lammy 2y agoI'm sick of mandatory TLS. All we did is make it harder for regular people to host their own pages, pushing them right into the hands of the big silos.