3 ms·
Please use HTTPS. I use HTTPS only. I don't think HTTP is acceptable for anyone let alone a technical blog post. It takes a few minutes, and it prevents me and
by tomtomtom777 5mo ago
Please use HTTPS.
I use HTTPS only. I don't think HTTP is acceptable for anyone let alone a technical blog post. It takes a few minutes, and it prevents me and all your visitors from getting all kinds of MITM injections.
Thanks.
- voidfunc 5mo agoMITM attack on a read-only text webpage... okay. More annoying is the slightly shiny/shaded text that is supposed to highlight something. Who chose this style palette?
- Aesthetikx 5mo agoHaha this is my blog -- its pretty new. I agree it's readability is less than ideal -- going to change it at some point. HTTPS as well probably at some point. Its been an experiment for me doing everything by hand. The entire blog is a large single Rakefile using Markaby :)
- himata4113 5mo agocheck out certbot + install certbot renew into crontab. Get the python3 variant the "native" package is outdated and removed from newer systems.
- lentil_soup 5mo agofor what is worth, I actually liked the shaded links, they made me smile :)
- zzo38computer 5mo agoEven just disabling CSS makes it readable. For HTTPS, I think that (like someone else mentioned) it should be made optional (at least for read-only access to public files) rather than mandatory.
- foobiekr 5mo agoIt’s html. Which is code that your browser executes. Millions of routers are compromised. BGP attacks happen. Anything http stands out as an interesting target for injection. This position is foolish. It’s not a major ask to enable https.
- themafia 5mo agoThe browser still has to execute code over HTTPS. You've just moved the injection perimeter from inside my own network into the providers website. I don't think you've fundamentally changed your level of risk unless you spend a huge amount of time browsing on shared password WPA protected wifi networks. You cannot browse to sites under any regime and execute code while expecting security to exist.
- pavon 5mo agoFor a random blog you have never visited before and have no reason to trust. It could attempt to do all the malicious things that you are worried a man in the middle would do.
- toast0 5mo ago> BGP attacks happen. If you control the IP a domain name points to, you can get a certificate issued. Https might help on a small BGP takeover, but it might very well not.
- himata4113 5mo agoI think you would have a better argument if you said something like: "I don't want my ISP knowing about the content I read" or something along those lines. MITM for a text download is like saying we have to have https for dns (yes DoH exists now), but the point still stands. You aren't sending any sensitive data to the website, MITM is unlikely.
- brewmarche 5mo agoWithout HTTPS someone could alter the content, spread false information, inject ads, malware, and other stuff, redirect to some other site, … (This is a general remark, but it goes for a blog post like this as well.)
- Joker_vD 5mo agoThe site owners could do all of that even with HTTPS, and no-one would revoke their certs. Just saying. And the best Windows malware is actually digitally signed.
- himata4113 5mo agoIt's still a weak argument since it's extremely rare in practice that's why I suggested blaming the ISP instead since ISP's are the ones that have historically tampered with http content.
- foobiekr 5mo agoAttacks in general are all rare in practice in the grand scheme of the internet. So?
- himata4113 5mo agoYes, that's why you present a better argument, that's the entire conversation.
- reaperducer 5mo agoNot everyone has to prepare their home for a leopard attack.
- Fwirt 5mo agoIt also prevents all kinds of clients who (for various reasons) can't implement SSL from visiting your website. I'm sure this is a "small web" blog, whose author wants to be visited by e.g. a Commodore 64, an OS 9 iMac, or somebody who just wants to telnet in. If the sensitivity of the information on this page was critical or you were going to be submitting information then by all means yes, SSL is important, but if you're going to be reading a personal blog about calendars then http is probably fine. Of course the ideal solution is offering both and letting the client choose.
- hamdingers 5mo agoSurprised this is downvoted. Chrome forces me to click through a warning to even visit HTTP sites nowadays.
- LtWorf 5mo agoYup, very secure. Then every single IT department installs a cert on the machines to MITM everything.
- hamdingers 5mo agoI have no idea what you're trying to say, there's no IT department managing my laptop and none of the IT departments I've worked in or with "MITM everything." Do you want to try again?
- pc86 5mo agoOn the flip side, every company I've ever worked for has installed trusted company certs on their computers and do MITM everything.
- Joker_vD 5mo agoYep. You apparently need HTTPS for intranet resources too, or you can't develop/use web-apps in Chrome, and since no self-respecting CA would certify your localhost, internal homegrown CA it is, baby — and given the web runs on the lovely model "any CA can attest any website; okay, maybe CAA is not a bad idea"...
- NoahZuniga 5mo agoEven with CAA records, any CA can still create a cert for any website. So if you're worried about an untrustworthy CA, then this won't help you. It could make it less likely for a CA with buggy code to accidentally issue a cert for your domain.
- stronglikedan 5mo ago
- pc86 5mo agoMan I really hope this doesn't get autoflagged because people need to see that this is an opinion people actually have, and what the (justified) reaction to it is. HTTPS on a blog does nothing. It doesn't protect you from anything. I guarantee you're not getting "all kinds of MITM injections" on this block of text. The only reasonable desire I can think of for "HTTPS everywhere" is hiding the content from your ISP but a) they still see the URL so they can get the content if they want it, and b) if you're so worried about that, use a VPN which coincidentally is even better because it will also hide the URL, and most importantly c) it puts the onus on you, the person who wants the thing, instead of hundreds or thousands or tens of thousands of text-only website owners who rightly couldn't care less about HTTPS.
- foobiekr 5mo ago>I guarantee you're not getting "all kinds of MITM injections" on this block of text You actually can’t guarantee anything of the sort. BGP hijacks are real.
- rnhmjoj 5mo ago> they still see the URL so they can get the content if they want it That's incorrect, a MitM can only reveal the server hostname by inspecting the SNI during the TLS handshake, but the HTTP request, including the URL and headers, is encrypted.
- pc86 5mo agoSurely your ISP can see every URL you visit if they have a reason to? They're routing the traffic.
- rnhmjoj 5mo agoNo they can't. They obviously know the IP addresses, but that's not terribly useful since everything is behind a cloudflare proxy nowadays. The server hostname may provide some more information, if the server doesn't support ECH [1], but the full URL is encrypted. https://en.wikipedia.org/wiki/Server_Name_Indication#Encrypted_Client_Hello https://en.wikipedia.org/wiki/Server_Name_Indication#Encrypt...
- 1-more 5mo agoI can't view this blog on my work laptop. Runs afoul of our firewall. Self signed certs do too.