Earlier quoted context omitted.
Parent poster might not be from an English-speaking background.
I am not, sort of. You can refer to a country by "she", so why is it inappropriate for a company? I don't see any issues. You can view a company as a mother too.
Google Will Soon Shame All Websites That Are Unencrypted
231–240 of 369 posts
Re: Google Will Soon Shame All Websites That Are Unencrypted
#232In the hopes that it will help spread adoption of HTTPS, I wrote a web server that serves your sites over HTTPS by default, using Let's Encrypt: https://caddyserver.com - It also redirects HTTP -> HTTPS.[1] There's a lot of misinformation out there about certificates and HTTPS, but don't let it stop you from encrypting your site. Regardless of Google's move, there is no excuse for any site not to be served encrypted…
Sorry but I actualy can't load the website because of an HTTPS error (Firefox 43/Linux) (Error code : sec_error_ocsp_old_response).
Re: Google Will Soon Shame All Websites That Are Unencrypted
#233Is there a good guide on making S3 sites work with SSL?
[0]: https://aws.amazon.com/blogs/aws/new-aws-certificate-manager... [1]: http://docs.aws.amazon.com/acm/latest/userguide/gs.html
Re: Google Will Soon Shame All Websites That Are Unencrypted
#234Earlier quoted context omitted.
No offense intended with this, but, as a web developer, what the heck are you doing creating your site on SquareSpace? Shouldn't you...I dunno...develop your own web site?
Because they don't get paid to build their own stuff. They get paid to do work for clients. A variation on the "shoemaker has no shoes."
Re: Google Will Soon Shame All Websites That Are Unencrypted
#235How will this impact page-speed? I recall switching the product pages of an e-comm site, which had up to 50 small images per page, from https to http and the change very significantly increased page load speed for the end user
Re: Google Will Soon Shame All Websites That Are Unencrypted
#236Earlier quoted context omitted.
I work for a SaaS company, we absolutely have customers who email us complaining about putting credit cards in a page served over http.
Certainly, and I would be one of them. I'm not saying nobody does care or that nobody should, only that enough people don't care enough to make this "red X of shame" that shameful, really. Chrome and Firefox have both had to take extreme measures for very similar things, such as web sites using expired (or even unvalidated/spoofed) SSL certificates. Google even reported that using a giant red page with warning labels…
Re: Google Will Soon Shame All Websites That Are Unencrypted
#237Earlier quoted context omitted.
I don't like this because I've always thought that HTTPS shouldn't be a mandatory baseline. It doesn't make a whole lot of sense to me that a random website with no financial transactions or anything should require HTTPS. [Edit: And thus, it makes less sense to me that the site should be penalized by anyone for NOT having it.] "Ah, yes. Bob's Trivia Emporium has HTTPS. I know this is really Bob's site and that the da…
HTTPS assures the integrity of the data transferred is from the origin domain, so it prevents your ISP from injecting additional ads into tour site, which some ISPs like to do [1]. [1]: http://arstechnica.com/tech-policy/2014/09/why-comcasts-java...
Re: Google Will Soon Shame All Websites That Are Unencrypted
#238Earlier quoted context omitted.
Of course, but there's a general expectation that stuff served over HTTP isn't sensitive. Breaking HTTPS where it's deliberately used is something that certainly deserves a warning.
> Of course, but there's a general expectation that stuff served over HTTP isn't sensitive. For us, sure. For the other 95% of the population, not really, which is why Google is doing this
I'm absolutely not arguing against such warnings for HTTP.
Re: Google Will Soon Shame All Websites That Are Unencrypted
#239Why don't I like this? I don't think it's HTTPS.... I think I don't like that one company has this much power over the web. This seems awfully familiar...
I don't like this because I've always thought that HTTPS shouldn't be a mandatory baseline. It doesn't make a whole lot of sense to me that a random website with no financial transactions or anything should require HTTPS. [Edit: And thus, it makes less sense to me that the site should be penalized by anyone for NOT having it.] "Ah, yes. Bob's Trivia Emporium has HTTPS. I know this is really Bob's site and that the da…
Looked at another way: Is there any reason http should not be secured with some sort of privacy and integrity check?
Re: Google Will Soon Shame All Websites That Are Unencrypted
#240Earlier quoted context omitted.
I am not, sort of. You can refer to a country by "she", so why is it inappropriate for a company? I don't see any issues. You can view a company as a mother too.
One of the reasons a country has feminine gender is the association with the mother land (ie. one's native country).