4 ms·
I realise I'm going to be in the 0.1% minority on this, but yep, I do. Three reasons. First, I've been enough places where Internet connectivity is so poor tha
by backwoodshacker 13y ago
I realise I'm going to be in the 0.1% minority on this, but yep, I do. Three reasons.
First, I've been enough places where Internet connectivity is so poor that HTTPS effectively breaks the connection. I used to stay half the week somewhere where the only connectivity was a dire, over-saturated 3G link. I couldn't browse HTTPS sites unless I was very lucky.
Second, I'm uneasy with the implication that "HTTPS=secure", in that it absolves the user of taking any responsibility for their own security. A site can require a HTTPS connection and still store the password in cleartext, for example; so unless you have a unique password, this "secure" site can still screw you. Yeah, I know HN readers understand the difference, but IMX most people dimly understand a binary distinction between "secure site" and "not secure site" and that's it.
Third and related, the corollary of "HTTPS=secure" is that "sites that only use HTTP = insecure". This is leading to a requirement that any guy who builds a website with login functionality needs to implement HTTPS, and that saddens me. The web becomes less democratic, less meritocratic, the more technical hurdles we require.
But, like I say, I realise 99.9% of people disagree with me.
- sitkack 13y agoIf this is your situation, you have other technical problems that, yes 99.99% of the people do not have. Something like a UDP proxy with FEC and proxy side stripping of cruft and external requests. Downgrading from https -> http is only solving a portion of your problem.
- dragonwriter 13y ago> Third and related, the corollary of "HTTPS=secure" is that "sites that only use HTTP = insecure". This is leading to a requirement that any guy who builds a website with login functionality needs to implement HTTPS, and that saddens me. HTTPS may not be secure, but HTTP (over the public internet, at least) is definitely insecure. If you have login functionality that matters, rather than serving as a very basic deterrent to accidentally getting somewhere you shouldn't be, yes, you need to use HTTPS.