3 ms·
>(thus making the page load slower) The difference is tiny. If your images are on the same domain as the html, you'll have no extra overhead from the ssl hands
by praxulus 14y ago
>(thus making the page load slower)
The difference is tiny. If your images are on the same domain as the html, you'll have no extra overhead from the ssl handshake (thanks to http keepalive), and the symmetric encryption used in an existing ssl connection will have a negligible impact on performance.
I can think of two reasons you want https, even for just images:
1) Even though modifying an image in flight will probably not have major security implications, you can't be sure. Perhaps a carefully edited and resized image could alter the layout of a form, tricking the careless user into publishing information they didn't mean to.
2) Perhaps your adversary is just a teenager bothering people trying to be productive at a coffee shop. Including a 10000x10000 image that makes the page unusable, or replacing your logo with porn isn't exactly something you want, even if it doesn't compromise anybody's bank account.
- papsosouid 14y agoHTTP keepalives just means you only need to negotiate two extra SSL connections instead of n (n being the number of images in the page). The overhead of that is certainly noticeable. If there's no actual benefit, then it shouldn't be in his list of "stuff you have to do (and nobody actually does)".
- praxulus 14y agoBut for most websites, it is something you have to do. Ruining the layout of your page is about as bad as any other DoS attack for most of the afflicted users.