Live data from Hacker News

Chrome will mark all HTTP sites as ‘not secure’ starting in July

theverge.com

141–143 of 143 posts

Re: Chrome will mark all HTTP sites as ‘not secure’ starting in July

#141
post #139

Earlier quoted context omitted.

It's easy for people like us to set it up. I've set up Letsencrypt many, many times. Now, imagine you are Joe Blow hosting his blog on some small web host that barely supports Wordpress. Logging into CPanel is confusing to you. How do you deploy SSL?

that is a fair point.

It looks like CPanel does support a letsencrypt plugin, which is really cool: https://blog.cpanel.com/announcing-cpanel-whms-official-lets...

However, I have to wonder how many hosts actually enable it...

Re: Chrome will mark all HTTP sites as ‘not secure’ starting in July

#143

Earlier quoted context omitted.

If a hostile controls a DNS server, you are hosed anyway.

If the sites you care about are using HSTS (and they're in the HSTS preload list, or you've visited them before from this device), then the worst the attacker can do is deny you from accessing them.

HSTS depends on DNS and NTP.
Post reply on HN