Live data from Hacker News

Google Will Soon Shame All Websites That Are Unencrypted

motherboard.vice.com

201–210 of 369 posts

Re: Google Will Soon Shame All Websites That Are Unencrypted

#201
post #91

Earlier quoted context omitted.

Sure they can. Your ISP can easily MitM you.

Not without throwing cert errors on every site I visit. The only way they can MITM me is if they compromise my PC as well and install their root CA.

Ah. True, my mistake.

Re: Google Will Soon Shame All Websites That Are Unencrypted

#202
post #167

Earlier quoted context omitted.

> You can pretty much say Yahoo actually "put herself above others" Do you mean `itself`? Since when are tech companies assigned genders?

Parent poster might not be from an English-speaking background.

I am not, sort of. You can refer to a country by "she", so why is it inappropriate for a company? I don't see any issues. You can view a company as a mother too.

Re: Google Will Soon Shame All Websites That Are Unencrypted

#204
post #166

This is stupid. Making https a requirement will break most web pages on hardware older than 2005 or so. This sucks for anyone without money.

Yes let's cripple the web by continuing to use unencrypted http, just because computers from 15 years ago won't be able to properly display some webpages...

Re: Google Will Soon Shame All Websites That Are Unencrypted

#206

I used Cloudflare's free SSL - is this enough? https://www.soundshelter.net

Yes. Google can't know what happens between Cloudflare and your server. (Communication there is also less likely to be intercepted as between the user's browser and the internet.)

Good to know - thanks

Re: Google Will Soon Shame All Websites That Are Unencrypted

#207

Consider this: - Squarespace doesn't support SSL (other than on their ecommerce checkout pages) [1] - Weebly only allows it on their $25/mo business plan [2] - Wordpress.com doesn't support SSL for sites with custom domains [3] - If you've never experienced the process of requesting, purchasing, and then installing an SSL certificate using a hosting control panel like Plesk or cPanel, let me tell you–it's a nightmare…

DreamHost now supports Let's Encrypt through their admin panel. The only instructions, however, are a community-maintained wiki page that is already outdated, referring to panel menus that no longer exist. I successfully obtained my certificate, but it was not easy.

Based on your comment, I went over to see if I could obtain a certificate.

It took all of 5 seconds for me to do - it's all automated via the admin panel now. Just tick the box to make your site secure. Looks like DH has resolved any initial issues they had.

Re: Google Will Soon Shame All Websites That Are Unencrypted

#208
post #63
post #45

Earlier quoted context omitted.

They are a platinum sponsor of Letsencrypt, so...done?

That doesn't mean anything other than "we like the idea, you convinced us, we have some budget, we will sponsor in some way money and human resource."

It means they are supporting a project that provides free SSL certificates. Which more than solves great-grandparent's quip.

Re: Google Will Soon Shame All Websites That Are Unencrypted

#209

Earlier quoted context omitted.

Yeah I'm all for SSL shaming but my personal site with SquareSpace is about to look like shit for me since I'm a web developer. I mean as a web developer it's not going to look good if your portfolio is shown with a security warning. I wonder if SquareSpace is going to finally fix their shit or if I'm going to have to move elsewhere which is going to be a pain (I went with SquareSpace because I didn't want to be asse…

No offense intended with this, but, as a web developer, what the heck are you doing creating your site on SquareSpace? Shouldn't you...I dunno...develop your own web site?

Because they don't get paid to build their own stuff. They get paid to do work for clients. A variation on the "shoemaker has no shoes."
Post reply on HN