Live data from Hacker News

Announcing Free and Automated SSL Certs

blog.heroku.com

1–10 of 79 posts

Re: Announcing Free and Automated SSL Certs

#4
Free SSL.. for all paid dynos. Apparently, if you're developing an application, you are expected to be okay with having your stuff MITMed.

Yes, this is me being excessively negative. Not having SSL-by-default in 2017 is excessively stupid. The certs are free, the system fully automated from both sides. Why hold back?

There is no excuse for not having it system wide. Unencrypted HTTP needs to start being treated as the danger it is.

Re: Announcing Free and Automated SSL Certs

#5

Free SSL.. for all paid dynos. Apparently, if you're developing an application, you are expected to be okay with having your stuff MITMed. Yes, this is me being excessively negative. Not having SSL-by-default in 2017 is excessively stupid. The certs are free, the system fully automated from both sides. Why hold back? There is no excuse for not having it system wide. Unencrypted HTTP needs to start being treated as th…

Free dynos with a ____.herokuapp.com domain have SSL enabled by default, at no cost (under their wildcard certificate?). Seems the only missing case is when using a custom domain with a free dyno.

Re: Announcing Free and Automated SSL Certs

#6

Free SSL.. for all paid dynos. Apparently, if you're developing an application, you are expected to be okay with having your stuff MITMed. Yes, this is me being excessively negative. Not having SSL-by-default in 2017 is excessively stupid. The certs are free, the system fully automated from both sides. Why hold back? There is no excuse for not having it system wide. Unencrypted HTTP needs to start being treated as th…

Or you can just make use of .herokuapp.com" rel="nofollow">https://.herokuapp.com
Post reply on HN