does anyone know why libgen is still running over http? (But sincerely thanks for the site! it saved me on several occasions!)
They don't want the extra weak spot of certificate revocation being abused against them? Though I'm not sure how big of an issue this is; sci-hub is using https.
Also, Let's Encrypt doesn't even revoke certificates for malware and phishing sites. [1]
Maybe they're doing this for better caching performance? It makes SSL flood attacks impossible, but is that really worth it?
[1] https://community.letsencrypt.org/t/how-to-report-abuse/4110...