Live data from Hacker News

Google Will Soon Shame All Websites That Are Unencrypted

motherboard.vice.com

11–20 of 369 posts

Re: Google Will Soon Shame All Websites That Are Unencrypted

#11
Sounds good. I wonder when Google Cloud Storage will start supporting https on static websites hosted through them:

https://cloud.google.com/storage/docs/website-configuration?...

If they don't then they're not keeping up with hosting on Amazon's S3, which does support it.

Re: Google Will Soon Shame All Websites That Are Unencrypted

#12
post #9

Yeah. Still not paying for a cert on my person home-pages just so I can have my own page come up first when people google my (worldwide unique) name. That page contains static HTML and does not need SSL, and it's not "insecure" just because you may be on a network which MITMs traffic. That makes your network insecure, not my page. So yeah. Not interesting. Not worth it.

Just set mine up for free, today. Letsencrypt.org works great. I recommend the simp_le client.

Re: Google Will Soon Shame All Websites That Are Unencrypted

#13
They should do something useful for the web and remove most if not all the current root certificates. There are so many places that have what is essentially a master key to the internet - and that master key is only going to be more important as more and more sites become SSL.

Re: Google Will Soon Shame All Websites That Are Unencrypted

#14
post #9

Yeah. Still not paying for a cert on my person home-pages just so I can have my own page come up first when people google my (worldwide unique) name. That page contains static HTML and does not need SSL, and it's not "insecure" just because you may be on a network which MITMs traffic. That makes your network insecure, not my page. So yeah. Not interesting. Not worth it.

> That makes your network insecure, not my page.

At which hop does it stop being "my" network and starts being "our" network? Your webhost? Your IX? Your country?

You can't shift the responsibility; only you can definitively secure the content coming out of your webpage.

Re: Google Will Soon Shame All Websites That Are Unencrypted

#15
I think 80% of web sites will be labelled as red-unsafe.

SSL layer security is good but sometimes a certificate is expensive and not free. Suppose that you have 10 domains and not all of them are for SNS, banks and etc..

At what minimum cost will you purchase a HTTPS certificate?

Re: Google Will Soon Shame All Websites That Are Unencrypted

#17

I think 80% of web sites will be labelled as red-unsafe. SSL layer security is good but sometimes a certificate is expensive and not free. Suppose that you have 10 domains and not all of them are for SNS, banks and etc.. At what minimum cost will you purchase a HTTPS certificate?

nada.

http://letsencrypt.org/

Re: Google Will Soon Shame All Websites That Are Unencrypted

#19
Just enabled Chrome to show the little crosses by default for http:// and I already like having this showing. If you wish to be an early adopter go to:

chrome://flags/#mark-non-secure-as

It is good to see how sites that matter are mostly https:// already for me. The http:// tabs I have open such as this article actually are insecure when you think about the amount of trackers on them, so the 'x' is very apt.

Re: Google Will Soon Shame All Websites That Are Unencrypted

#20
For Google, it’s not just about providing a secure environment and secure websites. In fact, Google actually has a monetary incentive to get as many websites to move over to HTTPs as possible: convincing website owners to move to HTTPs will help get rid of competing ad networks.
Post reply on HN