Plaintext HTTP in a Modern World
1–10 of 78 posts
Re: Plaintext HTTP in a Modern World
#2If you want the web to be free and open, and you run a personal website, please consider providing HTTP+HTTPS.
Re: Plaintext HTTP in a Modern World
#3Its like an hours work to set up.
Re: Plaintext HTTP in a Modern World
#4Everything in this article rings true. But there's more. HTTPS only, combined with almost everyone only using LetsEncrypt (a great service), leads to massive concentration of value for any internal corruption at LE or external political (or other) pressures on LE. The more browsers refuse to show HTTP, the more people in LE, the greater prize it is for those that want to control what is seen. If you want the web to b…
So simply having the certificate does not mean one can read the traffic without conducting a man-in-the-middle attack.
This means that anyone who could read traffic from a HTTPS connection could read it from a HTTP connection just as easy.
The arguement seems to boil down to, everyone uses a master lock, some people can open master locks, please consider leaving your locker unlocked... why?
Re: Plaintext HTTP in a Modern World
#5Re: Plaintext HTTP in a Modern World
#6Re: Plaintext HTTP in a Modern World
#7It's not only about security. I wonder if it happens in other countries too - here in Russia ISPs used to inject advertisements directly into HTTP traffic which was very annoying and now they inject propaganda justifying the war. Fortunately very few sites use HTTP nowadays compared to 10 years ago, so I haven't seen such ads in a while.
Re: Plaintext HTTP in a Modern World
#8Not sure I understand the concern about access from “modern embedded devices”. Something like a Raspberry Pi, or really anything with a decent ARM processor, can easily handle TLS.
Re: Plaintext HTTP in a Modern World
#9I also run an upstream SSL-bump proxy for my own older devices, and a small community of others, allowing us to browse the modern web (or at least, those sites that will still render on older browsers). The LE service is so important for certain applications and users, but I'm saddened that the push for HTTPS seemed to require the death of HTTP.
I appreciate the OP sharing his nginx config, and the few of you who replied with additional thoughts.
Re: Plaintext HTTP in a Modern World
#10Ironically, the article redirects http to https