Earlier quoted context omitted.
Most shared hosting accounts charge extra for a dedicated IP address, both for setup and on a monthly basis. Don't underestimate how many blogs, churches, small businesses, etc still use services like that. To be fair, many of those sites probably ARE insecure, but it seems to be a little bit overkill to "shame" them for not implementing encryption.
SSL hasn't required a separate IP since Windows XP. And XP no longer has any security support, so anyone running it has bigger problems.
Google Will Soon Shame All Websites That Are Unencrypted
181–190 of 369 posts
Re: Google Will Soon Shame All Websites That Are Unencrypted
#182This is stupid. Making https a requirement will break most web pages on hardware older than 2005 or so. This sucks for anyone without money.
Re: Google Will Soon Shame All Websites That Are Unencrypted
#183Which is hilarious because the reason I can't switch The New Yorker website to HTTPS is because of ads - which I'm getting from Google DFP which allows non-secure ad assets. In short; Google will penalize me because I use Google. The universe has a sense of humor.
Similarly, Google claimed they would start penalizing websites that showed full-page ads for mobile apps instead of showing you the website. But every single time I try to get to Gmail, or Drive, or Calendar, or any Google service on the web using a mobile device, I'm shown a full page ad for a mobile app. Google has been doing this for years, and it seems like it's also been a year since they said they'd punish all…
I understand not wanting an application for a news website or something like that but something you use often like google calendar it would seem like the application would be better than the mobile page.
Re: Google Will Soon Shame All Websites That Are Unencrypted
#184Earlier quoted context omitted.
Yeah I'm all for SSL shaming but my personal site with SquareSpace is about to look like shit for me since I'm a web developer. I mean as a web developer it's not going to look good if your portfolio is shown with a security warning. I wonder if SquareSpace is going to finally fix their shit or if I'm going to have to move elsewhere which is going to be a pain (I went with SquareSpace because I didn't want to be asse…
No offense intended with this, but, as a web developer, what the heck are you doing creating your site on SquareSpace? Shouldn't you...I dunno...develop your own web site?
Re: Google Will Soon Shame All Websites That Are Unencrypted
#185Earlier quoted context omitted.
HTTPS does not kill referrer or referer headers. See https://referer.rustybrick.com/
..so why are all of the search terms suddenly gone from google searche referer headers? Which happened at the same time google defaulted to https?
Re: Google Will Soon Shame All Websites That Are Unencrypted
#186This is how it always should have been. It was mind boggling that mixed content was "insecure" but HTTP was "secure." HTTP is and always has been insecure and should be marked as such. I know there are a few people who will moan and groan about how overkill HTTPS is, but this isn't about banning HTTP it is just about reminding users that they shouldn't be entering sensitive information into a HTTP site. Even phishing…
HTTP was never marked as secure. Mixed content was marked insecure because there were assets on the page that might not be from where you think they were from. It was an indicator that the little https lock in the URL bar wasn't telling you the whole story.
Which is fair, given that I bet you'd get about a 5% or less recognition rate if you polled a random sampling of people on whether they could define "HTTPS" / "SSL" / "TLS" / "That lock thingie" to any degree of accuracy.
A server shouldn't have the opportunity to serve an insecure connection to the user without the user being made explicitly aware of that fact.
Re: Google Will Soon Shame All Websites That Are Unencrypted
#187Earlier quoted context omitted.
Similarly, Google claimed they would start penalizing websites that showed full-page ads for mobile apps instead of showing you the website. But every single time I try to get to Gmail, or Drive, or Calendar, or any Google service on the web using a mobile device, I'm shown a full page ad for a mobile app. Google has been doing this for years, and it seems like it's also been a year since they said they'd punish all…
No offense meant but why not get the app? I understand not wanting an application for a news website or something like that but something you use often like google calendar it would seem like the application would be better than the mobile page.
If they want to show full-page ads and be super annoying, then fine, I'll deal with it. But don't pretend to be against it when you do the same practice yourself.
Re: Google Will Soon Shame All Websites That Are Unencrypted
#188Earlier quoted context omitted.
Not without throwing cert errors on every site I visit. The only way they can MITM me is if they compromise my PC as well and install their root CA.
... or rather get an intermediate certificate from one of the umpteen root CAs your operating system embeds by default. Is VeriSign going to refuse a certificate to AT&T?
I certainly hope so.
Re: Google Will Soon Shame All Websites That Are Unencrypted
#189Re: Google Will Soon Shame All Websites That Are Unencrypted
#190Earlier quoted context omitted.
Yeah I'm all for SSL shaming but my personal site with SquareSpace is about to look like shit for me since I'm a web developer. I mean as a web developer it's not going to look good if your portfolio is shown with a security warning. I wonder if SquareSpace is going to finally fix their shit or if I'm going to have to move elsewhere which is going to be a pain (I went with SquareSpace because I didn't want to be asse…
No offense intended with this, but, as a web developer, what the heck are you doing creating your site on SquareSpace? Shouldn't you...I dunno...develop your own web site?