Live data from Hacker News

Google Will Soon Shame All Websites That Are Unencrypted

motherboard.vice.com

181–190 of 369 posts

Re: Google Will Soon Shame All Websites That Are Unencrypted

#181
post #48

Earlier quoted context omitted.

Most shared hosting accounts charge extra for a dedicated IP address, both for setup and on a monthly basis. Don't underestimate how many blogs, churches, small businesses, etc still use services like that. To be fair, many of those sites probably ARE insecure, but it seems to be a little bit overkill to "shame" them for not implementing encryption.

SSL hasn't required a separate IP since Windows XP. And XP no longer has any security support, so anyone running it has bigger problems.

Guess you're right, fair enough. I still don't agree with putting a scarlet letter on these types of sites though.

Re: Google Will Soon Shame All Websites That Are Unencrypted

#183
post #76
post #64

Which is hilarious because the reason I can't switch The New Yorker website to HTTPS is because of ads - which I'm getting from Google DFP which allows non-secure ad assets. In short; Google will penalize me because I use Google. The universe has a sense of humor.

Similarly, Google claimed they would start penalizing websites that showed full-page ads for mobile apps instead of showing you the website. But every single time I try to get to Gmail, or Drive, or Calendar, or any Google service on the web using a mobile device, I'm shown a full page ad for a mobile app. Google has been doing this for years, and it seems like it's also been a year since they said they'd punish all…

No offense meant but why not get the app?

I understand not wanting an application for a news website or something like that but something you use often like google calendar it would seem like the application would be better than the mobile page.

Re: Google Will Soon Shame All Websites That Are Unencrypted

#184

Earlier quoted context omitted.

Yeah I'm all for SSL shaming but my personal site with SquareSpace is about to look like shit for me since I'm a web developer. I mean as a web developer it's not going to look good if your portfolio is shown with a security warning. I wonder if SquareSpace is going to finally fix their shit or if I'm going to have to move elsewhere which is going to be a pain (I went with SquareSpace because I didn't want to be asse…

No offense intended with this, but, as a web developer, what the heck are you doing creating your site on SquareSpace? Shouldn't you...I dunno...develop your own web site?

[deleted]

Re: Google Will Soon Shame All Websites That Are Unencrypted

#185

Earlier quoted context omitted.

HTTPS does not kill referrer or referer headers. See https://referer.rustybrick.com/

..so why are all of the search terms suddenly gone from google searche referer headers? Which happened at the same time google defaulted to https?

Did you read the page I linked to? My referer was https://encrypted.google.com/search?hl=en&q=What%20Is%20My%2...

Re: Google Will Soon Shame All Websites That Are Unencrypted

#186
post #75

This is how it always should have been. It was mind boggling that mixed content was "insecure" but HTTP was "secure." HTTP is and always has been insecure and should be marked as such. I know there are a few people who will moan and groan about how overkill HTTPS is, but this isn't about banning HTTP it is just about reminding users that they shouldn't be entering sensitive information into a HTTP site. Even phishing…

HTTP was never marked as secure. Mixed content was marked insecure because there were assets on the page that might not be from where you think they were from. It was an indicator that the little https lock in the URL bar wasn't telling you the whole story.

I think this is at the core of Google's thinking on this: unless presented with a negative, users' assumptions are that they're secure.

Which is fair, given that I bet you'd get about a 5% or less recognition rate if you polled a random sampling of people on whether they could define "HTTPS" / "SSL" / "TLS" / "That lock thingie" to any degree of accuracy.

A server shouldn't have the opportunity to serve an insecure connection to the user without the user being made explicitly aware of that fact.

Re: Google Will Soon Shame All Websites That Are Unencrypted

#187
post #76

Earlier quoted context omitted.

Similarly, Google claimed they would start penalizing websites that showed full-page ads for mobile apps instead of showing you the website. But every single time I try to get to Gmail, or Drive, or Calendar, or any Google service on the web using a mobile device, I'm shown a full page ad for a mobile app. Google has been doing this for years, and it seems like it's also been a year since they said they'd punish all…

No offense meant but why not get the app? I understand not wanting an application for a news website or something like that but something you use often like google calendar it would seem like the application would be better than the mobile page.

I do have the app. And that fact makes this double-annoying. When trying to visit a website, I'm told not to do that. That would be annoying on its own, and in fact it was for the first few years that it happened. But that's not at all what is frustrating me right now. What's super annoying is that Google claimed last year that they would penalize websites that do this, because they find it annoying too. Except they have done no such thing. I'm calling out Google's hypocrisy on who gets to show full-page ads without being penalized - Google does and nobody else?

If they want to show full-page ads and be super annoying, then fine, I'll deal with it. But don't pretend to be against it when you do the same practice yourself.

Re: Google Will Soon Shame All Websites That Are Unencrypted

#188
post #106

Earlier quoted context omitted.

Not without throwing cert errors on every site I visit. The only way they can MITM me is if they compromise my PC as well and install their root CA.

... or rather get an intermediate certificate from one of the umpteen root CAs your operating system embeds by default. Is VeriSign going to refuse a certificate to AT&T?

>Is VeriSign going to refuse a certificate to AT&T?

I certainly hope so.

Re: Google Will Soon Shame All Websites That Are Unencrypted

#190

Earlier quoted context omitted.

Yeah I'm all for SSL shaming but my personal site with SquareSpace is about to look like shit for me since I'm a web developer. I mean as a web developer it's not going to look good if your portfolio is shown with a security warning. I wonder if SquareSpace is going to finally fix their shit or if I'm going to have to move elsewhere which is going to be a pain (I went with SquareSpace because I didn't want to be asse…

No offense intended with this, but, as a web developer, what the heck are you doing creating your site on SquareSpace? Shouldn't you...I dunno...develop your own web site?

No offense intended, but as a web developer, why the heck would I waste my time coding things from scratch, setting up tooling, deployment infrastructure and managing yet another server when I could use a service that does all of that for me? For certain contexts it is far superior. Right tool for the right job, and all that.
Post reply on HN