Live data from Hacker News

NeverSSL

neverssl.com

21–30 of 212 posts

Re: NeverSSL

#21
post #6

Earlier quoted context omitted.

http://captive.apple.com/ also. That's what Apple devices use when trying to present the login for a captive network.

Is that better in any way than using example.com?

Any site that doesn't redirect to the SSL version (if applicable) will work. The benefit of using something like captive.apple.com is that it's specifically designed to NOT use SSL in order to trigger redirects and such, whereas something like example.com just so happens to not redirect to their SSL version, so it's (essentially) guaranteed to work vs example.com who could decide in the future to redirect to their SSL version if they want

Re: NeverSSL

#23
post #16

Earlier quoted context omitted.

Is that better in any way than using example.com?

If I regularly used that as a known-good site that should be up with no SSL, I'd trust that an apple-maintained site (backed by akamai) would be up before "example.com". I'm sure there are plenty of others, but someone might remember that URL over another so I thought it would be helpful.

example.com is maintained by IANA. It's an official example address for documentation purposes. So on one hand, it will survive even if Apple disappears, on the other, they're likely not expecting any significant traffic.

Re: NeverSSL

#24
So, this is for use captive wi-fi portals that are served over HTTP that would otherwise not work when initially connecting to a site using HTTPS?

Re: NeverSSL

#26
post #22

Ah something for the day xkcd[1] makes https mandatory. 1. http://xkcd.com

Yep. I used to hit Reddit, but they went to SSL by default. Since then, I've had to route people to xkcd who didn't know how to get around this issue.

Re: NeverSSL

#27
post #6

Earlier quoted context omitted.

http://captive.apple.com/ also. That's what Apple devices use when trying to present the login for a captive network.

You can also use http://detectportal.firefox.com/ that we set up for FirefoxOS captive portal detection.

Is this also used in the new captive portal detection that's coming down the pipe for Firefox?

Re: NeverSSL

#28
post #16

Earlier quoted context omitted.

Is that better in any way than using example.com?

If I regularly used that as a known-good site that should be up with no SSL, I'd trust that an apple-maintained site (backed by akamai) would be up before "example.com". I'm sure there are plenty of others, but someone might remember that URL over another so I thought it would be helpful.

To be fair, example.com is on an anycasted CDN too and is owned by IANA.

Re: NeverSSL

#29

So, this is for use captive wi-fi portals that are served over HTTP that would otherwise not work when initially connecting to a site using HTTPS?

Yep. Most default browser homepages use SSL, as do many popular second locations like Facebook. It can get a bit annoying to remember who won't serve you SSL when you're waiting to get an approval page injected into your browsing, so this site promises to do it.

It's especially relevant now that Chrome is threatening a big unsecure site warning for HTTP pages, so many sites which don't strictly need security are going to switch.

Post reply on HN