At $previous_job we once turned on HTTPS for our entire customer website and online store, only to have our customer support team be bombarded by phone calls claiming that our "website was down." After much teeth gnashing and research, we determined that a large segment of our user base was still using WinXP and the encryption protocols we offered weren't available to them. We didn't think this would be a problem bec…
HTTPS on Stack Overflow: The End of a Long Road
31–40 of 183 posts
Re: HTTPS on Stack Overflow: The End of a Long Road
#32Wow, I didn't expect this ("switching" to HTTPS) to be so hard.
Re: HTTPS on Stack Overflow: The End of a Long Road
#33Earlier quoted context omitted.
Well if it wasn't for someone buying .com back in the day, we probably could have them. Oh and then buying . .com after browsers banned that one, which led to RFC 6125 rule clarifications and restrictions.
Hey, I'm pretty sure that the first real domain name hack was sex.net, which as the proud owner of ex.net [PS: or was it sexnet.com, as we also have exnet.com?] caused some upset for a while, though mainly to disappointed one-handed typists I believe... B^> BTW, did I blink and miss the "It really is all faster over HTTP/2, even given TLS" bit? My testing for my tiny lightweight sites close to their users (the opposi…
Re: HTTPS on Stack Overflow: The End of a Long Road
#34Re: HTTPS on Stack Overflow: The End of a Long Road
#35At $previous_job we once turned on HTTPS for our entire customer website and online store, only to have our customer support team be bombarded by phone calls claiming that our "website was down." After much teeth gnashing and research, we determined that a large segment of our user base was still using WinXP and the encryption protocols we offered weren't available to them. We didn't think this would be a problem bec…
Re: HTTPS on Stack Overflow: The End of a Long Road
#36Has anyone tried running Fastly behind Cloudflare? Are the tradeoffs worth it?
Re: HTTPS on Stack Overflow: The End of a Long Road
#37Re: HTTPS on Stack Overflow: The End of a Long Road
#38Note to self: Use subdirectories, not subdomains in the future
TLS kills this kind of "cool" features which is kind of sad :( Unless you can afford wildcard certs. What's the argument behind LetsEncrypt not doing that? Extended Validation stuff?
But it boils down to there being no practical way for Let's Encrypt to automatically validate that a wildcard certificate is safe to issue.
Re: HTTPS on Stack Overflow: The End of a Long Road
#39At $previous_job we once turned on HTTPS for our entire customer website and online store, only to have our customer support team be bombarded by phone calls claiming that our "website was down." After much teeth gnashing and research, we determined that a large segment of our user base was still using WinXP and the encryption protocols we offered weren't available to them. We didn't think this would be a problem bec…
Re: HTTPS on Stack Overflow: The End of a Long Road
#40Just a reminder, HTTPS isn't enough. Be sure to turn the other security knobs with headers... https://securityheaders.io/?q=https%3A%2F%2Fstackoverflow.co...
Wonder what the point is then.