Hopefully they will also introduce a standard and free way to get SSL certificates. I do not like the idea of having to buy new certificates every year (and all the hassle that comes with installing the certificates) just to maintain a very basic website.
https://letsencrypt.org/
Deprecating Non-Secure HTTP
21–30 of 318 posts
Re: Deprecating Non-Secure HTTP
#22If SSL doesn't change, this move will cut the little folks out of the internet. What are Mozilla's values?
Re: Deprecating Non-Secure HTTP
#23I should be happy about this -- who wouldn't want the entire web to be encrypted -- but SSL is so broken for normal people. SSL is expensive (wildcard certificates run $70 a year and up), confusing (how does one pick between the 200 different companies selling certificates?), and incredibly difficult to set up (what order should I cat the certificate pieces in again?). If SSL doesn't change, this move will cut the li…
Not great for people running small websites.
Re: Deprecating Non-Secure HTTP
#24I should be happy about this -- who wouldn't want the entire web to be encrypted -- but SSL is so broken for normal people. SSL is expensive (wildcard certificates run $70 a year and up), confusing (how does one pick between the 200 different companies selling certificates?), and incredibly difficult to set up (what order should I cat the certificate pieces in again?). If SSL doesn't change, this move will cut the li…
From the site: Let’s Encrypt is a new Certificate Authority: It’s free, automated, and open. Arriving Mid-2015
Re: Deprecating Non-Secure HTTP
#25Earlier quoted context omitted.
Nope. The goal is to make running a server only available to corporate entities. It reduce competition from folks like yourself.
If the cost of an SSL certificate is a barrier for you to compete, you should probably do something else.
I'm saddened that you are so economically prejudiced against potential content creators.
Re: Deprecating Non-Secure HTTP
#26For Tor and I2P hidden services, HTTPS is redundant so I don't really see the point in punishing people for things like this. Loopback sites are an obvious exception to the "HTTPS is better" rule as well.
Re: Deprecating Non-Secure HTTP
#27Earlier quoted context omitted.
If the cost of an SSL certificate is a barrier for you to compete, you should probably do something else.
Can you still serve a static site from AWS' S3 with an SSL cert? Last time I checked, you can't unless you use Cloudfront in front of it.
Re: Deprecating Non-Secure HTTP
#28Why do we have to pay for an SSL certificate? Shouldn't it be free?
The problem is that browsers have gone and made self-signed certs suspect, and yet not created, for example, a well-established foundation for signing such certs.
Re: Deprecating Non-Secure HTTP
#29For Tor and I2P hidden services, HTTPS is redundant so I don't really see the point in punishing people for things like this. Loopback sites are an obvious exception to the "HTTPS is better" rule as well.
Re: Deprecating Non-Secure HTTP
#30Earlier quoted context omitted.
Nope. The goal is to make running a server only available to corporate entities. It reduce competition from folks like yourself.
If the cost of an SSL certificate is a barrier for you to compete, you should probably do something else.