My website runs on a vps with NodeJS as the backend. I could easily self sign a certificate but chrome displays a huge warning to users. How about signing certificates for free google. Https is easy to implement but the fact that it costs is bs.
Google Will Soon Shame All Websites That Are Unencrypted
221–230 of 369 posts
Re: Google Will Soon Shame All Websites That Are Unencrypted
#222Earlier quoted context omitted.
If you don't have a way to confirm that the key you're seeing from the other site is right, you're inherently vulnerable to a man-in-the-middle attack which removes the benefits of the encryption against the attacker. https://en.wikipedia.org/wiki/Man-in-the-middle_attack httpS://en.wikipedia.org/wiki/Zooko's_triangle It's not clear that the certificate authority system was or is the best solution to this problem, bu…
However, having one and not the other isn't totally useless. Having the browser be able to track and tell me that "Though we aren't sure this is actually google.com, we do know that the exact same cert has been used the last 50 times you visited this website" is something I'd consider to be useful. (Actually, telling me if it changes would be the useful bit). That would be at least be useful for self-signed certs (th…
Re: Google Will Soon Shame All Websites That Are Unencrypted
#223The only situation where I still want to use HTTP is one page I serve, which uses websockets, and I don't want to use secure websockets, but that's the only exception.
I'm glad to be in this boat. Once again, it's mostly thanks to Let's Encrypt being awesome, and I'm thankful to it.
Re: Google Will Soon Shame All Websites That Are Unencrypted
#224Should static content be encrypted over https? I think it's fair for chrome to call out with an x as I've literally seen local lunch joints take orders with credit card info over http but to serve mostly static pages like the new yorker over http only means that the user's privacy is compromised in that people can see what you're reading - does that warrant down ranking searches? I'm just curious - I work mostly on p…
Because mobile carriers are given broad discretion to do whatever they want to do to your traffic. They cheerfully modify content, and have built infrastructure to do it even more.
Re: Google Will Soon Shame All Websites That Are Unencrypted
#225https://news.ycombinator.com/item?id=5238164 Still not solved... calm down Google!
Re: Google Will Soon Shame All Websites That Are Unencrypted
#226And I always thought TLS is the virtual equivalent to those TSA locks.
Re: Google Will Soon Shame All Websites That Are Unencrypted
#227My website runs on a vps with NodeJS as the backend. I could easily self sign a certificate but chrome displays a huge warning to users. How about signing certificates for free google. Https is easy to implement but the fact that it costs is bs.
LetsEncrypt offers free, automated certificates and is recognised in all major browsers (IE, Chrome, FF, Safari). https://letsencrypt.org/
Re: Google Will Soon Shame All Websites That Are Unencrypted
#228Re: Google Will Soon Shame All Websites That Are Unencrypted
#229Why don't I like this? I don't think it's HTTPS.... I think I don't like that one company has this much power over the web. This seems awfully familiar...
I don't like this because I've always thought that HTTPS shouldn't be a mandatory baseline. It doesn't make a whole lot of sense to me that a random website with no financial transactions or anything should require HTTPS. [Edit: And thus, it makes less sense to me that the site should be penalized by anyone for NOT having it.] "Ah, yes. Bob's Trivia Emporium has HTTPS. I know this is really Bob's site and that the da…
[1]: http://arstechnica.com/tech-policy/2014/09/why-comcasts-java...
Re: Google Will Soon Shame All Websites That Are Unencrypted
#230Earlier quoted context omitted.
No offense meant but why not get the app? I understand not wanting an application for a news website or something like that but something you use often like google calendar it would seem like the application would be better than the mobile page.
I do have the app. And that fact makes this double-annoying. When trying to visit a website, I'm told not to do that. That would be annoying on its own, and in fact it was for the first few years that it happened. But that's not at all what is frustrating me right now. What's super annoying is that Google claimed last year that they would penalize websites that do this, because they find it annoying too. Except they…
It really just shows the sad state of mobile advertising when they're showing you ads for an app you already have.