Live data from Hacker News

History of HTTPS Usage

jefftk.com

11–20 of 27 posts

Re: History of HTTPS Usage

#11
The funniest thing about HTTPS is that its transition/enforcement exposed a lot of people who don’t understand why we need HTTPS everywhere, even if there are no logins (!!!)

To this day, if you open Twitter, Facebook Groups or Discord, you’ll find people complaining about Google forcing HTTPS down people’s throat.

Re: History of HTTPS Usage

#12
post #8

Earlier quoted context omitted.

While it's certainly possible the ISP could extract the data (and might be forced to by some intelligence agency), it was also possible to just listen to the data in transit. Remember that these were the days of people sending data over telephone wires.

Other than eavesdrop, the biggest advantage of HTTPS for me is to stop nasty ISP that injecting advertisement or other code in HTTP page.

Also the biggest advantage of HTTPS for any bigco whose business model relies on showing you _their_ ads and no one else’s.

Re: History of HTTPS Usage

#13
post #11

The funniest thing about HTTPS is that its transition/enforcement exposed a lot of people who don’t understand why we need HTTPS everywhere, even if there are no logins (!!!) To this day, if you open Twitter, Facebook Groups or Discord, you’ll find people complaining about Google forcing HTTPS down people’s throat.

Plenty of them here on HN too.

Re: History of HTTPS Usage

#14

> This allowed for an enormous amount of things, but online shopping wasn't one of them. The problem was, sending credit card numbers over HTTP opened them up to theft: anyone between you and the server could keep a copy of your card information. In the 90s, what exactly would the attack vector have been? I don't imagine AOL would have wanted to steal people's credit cards. I find it odd that this was viewed as a con…

While it's certainly possible the ISP could extract the data (and might be forced to by some intelligence agency), it was also possible to just listen to the data in transit. Remember that these were the days of people sending data over telephone wires.

People routinely ordered by phone, reading out the card number to the person on the far end.

Re: History of HTTPS Usage

#15
post #8

Earlier quoted context omitted.

While it's certainly possible the ISP could extract the data (and might be forced to by some intelligence agency), it was also possible to just listen to the data in transit. Remember that these were the days of people sending data over telephone wires.

Other than eavesdrop, the biggest advantage of HTTPS for me is to stop nasty ISP that injecting advertisement or other code in HTTP page.

Can you not just choose a better ISP?

Re: History of HTTPS Usage

#16
post #15
post #8

Earlier quoted context omitted.

Other than eavesdrop, the biggest advantage of HTTPS for me is to stop nasty ISP that injecting advertisement or other code in HTTP page.

Can you not just choose a better ISP?

i think most people had the option to choose among two, or maybe if they were lucky three ISPs. only big cities had more, and the better alternative ISPs tended to be more expensive too. and since they were not exactly telling you in advance that they were going to do this and they often were locking you into one or two year minimum contracts, switching ISPs was and still is not a simple thing to do.

Re: History of HTTPS Usage

#17
post #11

The funniest thing about HTTPS is that its transition/enforcement exposed a lot of people who don’t understand why we need HTTPS everywhere, even if there are no logins (!!!) To this day, if you open Twitter, Facebook Groups or Discord, you’ll find people complaining about Google forcing HTTPS down people’s throat.

one of my biggest regrets is that in the early 2000s when i was contributing to a webserver project i suggested that we should not allow people to log in via http but instead enforce https for that. or rather, use https for login content and http for public content. the devs liked the idea and promptly implemented it with the result that while it now was no longer possible to log in via http the server also could not show public content over https.

Re: History of HTTPS Usage

#18
post #14

Earlier quoted context omitted.

While it's certainly possible the ISP could extract the data (and might be forced to by some intelligence agency), it was also possible to just listen to the data in transit. Remember that these were the days of people sending data over telephone wires.

People routinely ordered by phone, reading out the card number to the person on the far end.

I'm fairly sure this still happens. In 2013-2014 I worked for a company that does outsourced customer support and I worked in the department that handles customer support for logistics in a very famous fruit/computing company, via telephone.

If people ended up buying things from me, the standard practice was for them to read out their credit card details so I could purchase things for them, in their name.

Re: History of HTTPS Usage

#19

Makes me wonder what the history of HTTPS is on Hacker News. Does anyone know? Perhaps the dang (the moderator of Hacker News) knows…

Not a definite answer by any measure, but pg started linking to https://news... instead of http://news... sometime around 11 years ago: https://hn.algolia.com/?dateRange=all&page=0&prefix=true&que...

Before that, all http links instead.

Re: History of HTTPS Usage

#20
post #18
post #14

Earlier quoted context omitted.

People routinely ordered by phone, reading out the card number to the person on the far end.

I'm fairly sure this still happens. In 2013-2014 I worked for a company that does outsourced customer support and I worked in the department that handles customer support for logistics in a very famous fruit/computing company, via telephone. If people ended up buying things from me, the standard practice was for them to read out their credit card details so I could purchase things for them, in their name.

It absolutely is still accepted practice. I purchased a hotel reservation by phone mere months ago. Hyatt's website was giving me an error during checkout, so I called them, and they took down my CC over the phone.

This is why I find it strange that the idea of sending CC information over a dialup phone line was seen as unacceptable.

Post reply on HN