Live data from Hacker News

HTTPS on NYTimes.com

open.blogs.nytimes.com

141–150 of 167 posts

Re: HTTPS on NYTimes.com

#141

The thing the NYT needs to fix (as of earlier last year) is the fact that you can't cancel your subscription without calling them (which is not the case for signing up). I spent 20 minutes[1] on the phone telling them that yes, I really did want to cancel. It was a worse experience than dealing with Comcast, not least because I felt bad for the poor woman who obviously had some financial incentive to get me to stay o…

Very interesting. That's good to know - thank you. I was going to get a subscription for the first time starting in February. I'll have to reconsider that.

I've subscribed via the Play Store, canceling is easier than buying an app, no password, no checking.

In the "My Apps & Games" menu > "Subscriptions" > "NYT Digital Access" > "Manage Subscription" > "Cancel" > "Confirm".

Re: HTTPS on NYTimes.com

#142
post #138
post #48

Earlier quoted context omitted.

For our media website, it took us one year before we could move to HTTPS, mainly because of the AdServers which wasn't ready. We had to talk to each ad provider in order to ask them to upgrade to HTTPS. Unfortunately as media companies have most of their revenue from ads you just can't switch like that. Also, features that are now available once the HTTPS by default on a website, is the AMP, Notifications, HTTP2 (fas…

Google started the process of enforcing HTTPS on AdX about 2.5 years ago. Not implementing HTTPS in that large timeframe is rather inexcusable. It's just technical debt that you need to acknowledge, and then get rid of it.

Nowadays an Ad Server can call another one and so one, due to programmatic. So you might have one Ad server enforcing and serving their tags in HTTPS, but in the end the little local Ad Server which is part of a bigger network doesn't have the HTTPS and so his material isn't delivered.

Re: HTTPS on NYTimes.com

#143
post #28

They mention it has been a complex undertaking and not complete yet - does anyone know why they can't just sit a traffic manager in front of everything with SSL offloading? Also does anyone know what the new personalisation features are that they mention being able to offer now HTTPS in place?

At any large media organization, there are tremendous amounts of content no longer connected to any CMS that may have hard-coded insecure links/resources in them. Some of them may live on obscure servers or domains. Or the developers/journalists who worked on them and have knowledge of their construction are long gone. These pages are very laborious to find and update. If you don't mind 404ing or breaking a ton of yo…

Well, in our case that was the easiest thing to pick, thanks to the Report-Only option on the CSP header, we enabled it and in about a week, we got all our insecure links and resources.

We could also set a header forcing the browser to upgrade to secure when the resources are in the same domain.

Re: HTTPS on NYTimes.com

#144
post #2

Oh no, this was my go-to site whenever I had to login to public wifi and https wouldn't redirect :(

http://purple.com - also useful for seeing if someone's internet is working over the phone or not. "Go to purple.com and tell me what you see". Is the answer "purple"? Hooray!

Re: HTTPS on NYTimes.com

#145

The thing the NYT needs to fix (as of earlier last year) is the fact that you can't cancel your subscription without calling them (which is not the case for signing up). I spent 20 minutes[1] on the phone telling them that yes, I really did want to cancel. It was a worse experience than dealing with Comcast, not least because I felt bad for the poor woman who obviously had some financial incentive to get me to stay o…

This is what I like about Netflix. In their Help section, the top question under Account is how to cancel. But this probably reflects the fact that Netflix has money pouring in, while the NYT has more trouble finding paying subscribers.

Re: HTTPS on NYTimes.com

#146

The thing the NYT needs to fix (as of earlier last year) is the fact that you can't cancel your subscription without calling them (which is not the case for signing up). I spent 20 minutes[1] on the phone telling them that yes, I really did want to cancel. It was a worse experience than dealing with Comcast, not least because I felt bad for the poor woman who obviously had some financial incentive to get me to stay o…

This happened when I subscribed to the UK Times. But I emailed them to tell them I was in South Africa and wasn't going to waste money phoning them they did end up helping me via email.

Re: HTTPS on NYTimes.com

#147
post #96

"I'm all in favor of news sites using HTTPS, but I assume they're also going to pad all their articles to a uniform length?" Source: https://twitter.com/matthew_d_green/status/53504312624809574...

This isn't an "all or nothing" situation. Enabling HTTPS is a benefit even if it's not perfect. The integrity and authentication it provides are alone a MASSIVE benefit (especially for a news site). Now you'll know that your news is coming from their servers, and nobody else is tampering with it. Then taking into account that it does provide confidentiality, you get rid of "dragnet" style data gathering and inspectio…

"Now you'll know that your news is coming from their servers, and nobody else is tampering with it."

I'm a HTTPS noob, can you explain how or why someone would tamper it on normal HTTP? Who would care to target me and what are the chances that NYT has been tampered with ever before?

Re: HTTPS on NYTimes.com

#148
post #96

"I'm all in favor of news sites using HTTPS, but I assume they're also going to pad all their articles to a uniform length?" Source: https://twitter.com/matthew_d_green/status/53504312624809574...

This isn't an "all or nothing" situation. Enabling HTTPS is a benefit even if it's not perfect. The integrity and authentication it provides are alone a MASSIVE benefit (especially for a news site). Now you'll know that your news is coming from their servers, and nobody else is tampering with it. Then taking into account that it does provide confidentiality, you get rid of "dragnet" style data gathering and inspectio…

"Now you'll know that your news is coming from their servers, and nobody else is tampering with it."

I'm a HTTPS noob, can you explain how or why someone would tamper it on normal HTTP? Who would care to target me and what are the chances that NYT has been tampered with ever before?

Re: HTTPS on NYTimes.com

#149

Earlier quoted context omitted.

This isn't an "all or nothing" situation. Enabling HTTPS is a benefit even if it's not perfect. The integrity and authentication it provides are alone a MASSIVE benefit (especially for a news site). Now you'll know that your news is coming from their servers, and nobody else is tampering with it. Then taking into account that it does provide confidentiality, you get rid of "dragnet" style data gathering and inspectio…

"Now you'll know that your news is coming from their servers, and nobody else is tampering with it." I'm a HTTPS noob, can you explain how or why someone would tamper it on normal HTTP? Who would care to target me and what are the chances that NYT has been tampered with ever before?

I'll leave the "how" to any of the many resources out there that describe how HTTPS works. As to why, there's probably low likelihood that someone is tampering with your connection to the NYT. It's good practice, however, and is (largely) transparent to the user. My house may not have ever been broken into before, and likely not going to be broken into in the future, though I still lock my door.

Re: HTTPS on NYTimes.com

#150
post #57

Earlier quoted context omitted.

Yeah, that's a Comcast-level move, though to be fair, I tried to unsubscribe from The Economist a few years back and it was a nightmare as well [1], so maybe it's just that the news media industry puts all it's eggs in a different basket when it comes to UX. [1] http://www.economist.com/help/manageprintsubscription#cancel...

I tell you what, it sure made me wary of signing up for any more news media subscriptions, now or in the future. It seems almost hypocritical to complain about how people don't want to pay for quality news and then treat them like crap when they do (not that I'm ascribing this to any one person or organization).

Don't sign up for Adobe either then: They've had massively huge CC leaks (shows a lack of care for security) and their unsubscription page has been broken for years.
Post reply on HN