Live data from Hacker News

Enabling Secure HTTP for BBC Online

bbc.co.uk

61–63 of 63 posts

Re: Enabling Secure HTTP for BBC Online

#61

And just yesterday I told someone to visit BBC when trying to connect to public wifi that requires a redirect to a login page first. Guess I'm going to have to find a new go-to http site now

There really should be a new, better solution to captive portals.

There is! RFC 7710[1] specifies a DHCP option/RA extension that encodes the URL of the captive portal, s.t. when, e.g. DHCP completes, the connecting machine immediately knows what the captive portal URL is, and doesn't have to get MitM'd to know it.

[1]: https://tools.ietf.org/html/rfc7710

Re: Enabling Secure HTTP for BBC Online

#62
post #42

Earlier quoted context omitted.

Their traffic is too high for them to afford it (and probably wouldn't outweigh the SEO uplift)

Can I ask you why you say it would be too high for NYT to afford it, when many companies with significantly more traffic have site-wide TLS?

If your examples are Google or Amazon, then those have profits several orders of magnitude bigger than the likes of NYT.

Re: Enabling Secure HTTP for BBC Online

#63

Earlier quoted context omitted.

There really should be a new, better solution to captive portals.

There is! RFC 7710[1] specifies a DHCP option/RA extension that encodes the URL of the captive portal, s.t. when, e.g. DHCP completes, the connecting machine immediately knows what the captive portal URL is, and doesn't have to get MitM'd to know it. [1]: https://tools.ietf.org/html/rfc7710

You learn new things every day. I'd love to see this in greater adoption.
Post reply on HN