Live data from Hacker News

NeverSSL

fdbhclmrkstnvwxz.neverssl.com

151–160 of 206 posts

Re: NeverSSL

#151
post #131
post #66

http://neverssl.com/changes > I also want to keep neverssl.com ad free, but as it's now costing me about $2,000 a year to host it, […] Wait, how could hosting a static website cost $2k/year?!

that's either a lie, or that's because the owner doesn't care about saving costs. I've hosted more dynamic webpages with large amount of traffic on servers that were costing me 20$/month.

[deleted]

Re: NeverSSL

#152
post #131
post #66

http://neverssl.com/changes > I also want to keep neverssl.com ad free, but as it's now costing me about $2,000 a year to host it, […] Wait, how could hosting a static website cost $2k/year?!

that's either a lie, or that's because the owner doesn't care about saving costs. I've hosted more dynamic webpages with large amount of traffic on servers that were costing me 20$/month.

The owner is Colm MacCárthaigh https://twitter.com/colmmacc. He's a Senior Principal Engineer at AWS Networking and is the author of s2n - https://github.com/awslabs/s2n.

I'm pretty sure he knows what he's doing and it costs what it costs for a reason.

Re: NeverSSL

#153

Shortest SSL-free domain I've found is "x.com". Also works for email. Apologies to x@x.com (sorry Elon!).

That used to belong to a company selling a proprietary implementation of X11 a while back (I want to say MetroLink? They had ads in the Linux print magazines at the time).

Re: NeverSSL

#154
post #131

Earlier quoted context omitted.

that's either a lie, or that's because the owner doesn't care about saving costs. I've hosted more dynamic webpages with large amount of traffic on servers that were costing me 20$/month.

The owner is Colm MacCárthaigh https://twitter.com/colmmacc . He's a Senior Principal Engineer at AWS Networking and is the author of s2n - https://github.com/awslabs/s2n . I'm pretty sure he knows what he's doing and it costs what it costs for a reason.

No doubt he is smart, but it literally costs so much because he is using extremely expensive tools for that. It's literally static content.

Re: NeverSSL

#155

http://example.com also does this, albeit without the promise of never switching

I've always used terrible.com

It's just your standard parked domain. I typed it in when I was frustrated one time trying to log into a public wifi. It worked and I didn't even understand why back then.

Re: NeverSSL

#156
post #66

http://neverssl.com/changes > I also want to keep neverssl.com ad free, but as it's now costing me about $2,000 a year to host it, […] Wait, how could hosting a static website cost $2k/year?!

It just takes a few badly behaved scripts constantly polling the domain.

Re: NeverSSL

#157
post #77

Earlier quoted context omitted.

Can't do any useful caching for a purposefully cache-busting website

it's not cache-busting, it's captive-portal busting. there's no reason it couldn't be cached on some service that charges less for bandwidth than AWS does.

Read http://neverssl.com/changes

Re: NeverSSL

#158
post #69

Earlier quoted context omitted.

from the same page: > it's just a simple website hosted on AWS lots of ways of spending a lot of money on hosting a website on AWS. Hard to judge precisely without traffic numbers.

That page says 6 million hits per day.

1 raspberry pi 4 could handle this...

Re: NeverSSL

#159
post #131

Earlier quoted context omitted.

that's either a lie, or that's because the owner doesn't care about saving costs. I've hosted more dynamic webpages with large amount of traffic on servers that were costing me 20$/month.

The owner is Colm MacCárthaigh https://twitter.com/colmmacc . He's a Senior Principal Engineer at AWS Networking and is the author of s2n - https://github.com/awslabs/s2n . I'm pretty sure he knows what he's doing and it costs what it costs for a reason.

Maybe, but there are a bunch of smart folks here too, and no one can come up with a good reason for this costing $2k/year.

It's possible $166/mo is not enough of a hit on his income so as to be worth spending time optimizing (unlikely considering how little time it'd seemingly take to optimize), or since he works for AWS it could be sponsored (which would mean he has to justify the continued cost to his bosses when they ask about it).

All valid reasons, but not technical ones. Either there's some aspect of implementing this that we're not thinking of, or there are non-technical reasons involved that we're simply unaware of.

Re: NeverSSL

#160

"This website is for when you try to open Facebook, Google, Amazon, etc on a wifi network, and nothing happens. Type " http://neverssl.com" into your browser's url bar, and you'll be able to log on." I don't get it. How does browsing to http://neverssl.com help you to log in to other websites?

It lets you access the portal to connect to wifi by allowing the router to MITM the connection due to the lack of SSL and bypassing caching with the random subdomain. After successfully connecting through whatever custom router software you'll be able to log in to those other websites.

[deleted]
Post reply on HN