Live data from Hacker News

Google Will Soon Shame All Websites That Are Unencrypted

motherboard.vice.com

231–240 of 369 posts

Re: Google Will Soon Shame All Websites That Are Unencrypted

#231
post #167

Earlier quoted context omitted.

Parent poster might not be from an English-speaking background.

I am not, sort of. You can refer to a country by "she", so why is it inappropriate for a company? I don't see any issues. You can view a company as a mother too.

One of the reasons a country has feminine gender is the association with the motherland (ie. one's native country).

Re: Google Will Soon Shame All Websites That Are Unencrypted

#232
post #96

In the hopes that it will help spread adoption of HTTPS, I wrote a web server that serves your sites over HTTPS by default, using Let's Encrypt: https://caddyserver.com - It also redirects HTTP -> HTTPS.[1] There's a lot of misinformation out there about certificates and HTTPS, but don't let it stop you from encrypting your site. Regardless of Google's move, there is no excuse for any site not to be served encrypted…

Sorry but I actualy can't load the website because of an HTTPS error (Firefox 43/Linux) (Error code : sec_error_ocsp_old_response).

I just downloaded and installed Firefox 44 today and it works great. Clear your cache?

Re: Google Will Soon Shame All Websites That Are Unencrypted

#233

Is there a good guide on making S3 sites work with SSL?

You can use the new AWS Certificate Manager[0] with CloudFront[1], which you can attach to your S3 bucket. The docs aren't brilliant, though.

[0]: https://aws.amazon.com/blogs/aws/new-aws-certificate-manager... [1]: http://docs.aws.amazon.com/acm/latest/userguide/gs.html

Re: Google Will Soon Shame All Websites That Are Unencrypted

#234

Earlier quoted context omitted.

No offense intended with this, but, as a web developer, what the heck are you doing creating your site on SquareSpace? Shouldn't you...I dunno...develop your own web site?

Because they don't get paid to build their own stuff. They get paid to do work for clients. A variation on the "shoemaker has no shoes."

With that argument, there should be no marketing departments.

Re: Google Will Soon Shame All Websites That Are Unencrypted

#235

How will this impact page-speed? I recall switching the product pages of an e-comm site, which had up to 50 small images per page, from https to http and the change very significantly increased page load speed for the end user

I'll guess that the browser opened several connections to fetch all of the content (to work around broken http/1.1 pipelining) and needed to complete many tls handshakes. http2 probably would have done a better job.

Re: Google Will Soon Shame All Websites That Are Unencrypted

#236
post #77

Earlier quoted context omitted.

I work for a SaaS company, we absolutely have customers who email us complaining about putting credit cards in a page served over http.

Certainly, and I would be one of them. I'm not saying nobody does care or that nobody should, only that enough people don't care enough to make this "red X of shame" that shameful, really. Chrome and Firefox have both had to take extreme measures for very similar things, such as web sites using expired (or even unvalidated/spoofed) SSL certificates. Google even reported that using a giant red page with warning labels…

Right, and I guess I meant to imply that it is some of the unwashed non-elite masses that notice that stuff. Our product is for people who are bad at software and want an easier way to do task X, but they still know to look for the green lock. I don't have strong data but I'd just say-- don't underestimate the web knowledge of people who are mostly making cat pictures.

Re: Google Will Soon Shame All Websites That Are Unencrypted

#237

Earlier quoted context omitted.

I don't like this because I've always thought that HTTPS shouldn't be a mandatory baseline. It doesn't make a whole lot of sense to me that a random website with no financial transactions or anything should require HTTPS. [Edit: And thus, it makes less sense to me that the site should be penalized by anyone for NOT having it.] "Ah, yes. Bob's Trivia Emporium has HTTPS. I know this is really Bob's site and that the da…

HTTPS assures the integrity of the data transferred is from the origin domain, so it prevents your ISP from injecting additional ads into tour site, which some ISPs like to do [1]. [1]: http://arstechnica.com/tech-policy/2014/09/why-comcasts-java...

That doesn't convince me; it's like saying every Tom, Dick, and Harry should get encrypted phones because Verizon has the capability to tap into conversations. The onus should be on the provider, not the customer.

Re: Google Will Soon Shame All Websites That Are Unencrypted

#238
post #195

Earlier quoted context omitted.

Of course, but there's a general expectation that stuff served over HTTP isn't sensitive. Breaking HTTPS where it's deliberately used is something that certainly deserves a warning.

> Of course, but there's a general expectation that stuff served over HTTP isn't sensitive. For us, sure. For the other 95% of the population, not really, which is why Google is doing this

Yeah, but I'm just explaining why warnings for mixed content are more important than for plain HTTP.

I'm absolutely not arguing against such warnings for HTTP.

Re: Google Will Soon Shame All Websites That Are Unencrypted

#239

Why don't I like this? I don't think it's HTTPS.... I think I don't like that one company has this much power over the web. This seems awfully familiar...

I don't like this because I've always thought that HTTPS shouldn't be a mandatory baseline. It doesn't make a whole lot of sense to me that a random website with no financial transactions or anything should require HTTPS. [Edit: And thus, it makes less sense to me that the site should be penalized by anyone for NOT having it.] "Ah, yes. Bob's Trivia Emporium has HTTPS. I know this is really Bob's site and that the da…

Suppose you go to Bob's trivia emporium in your browser and a MITM inserts malicious javascript content into the response.

Looked at another way: Is there any reason http should not be secured with some sort of privacy and integrity check?

Re: Google Will Soon Shame All Websites That Are Unencrypted

#240

Earlier quoted context omitted.

I am not, sort of. You can refer to a country by "she", so why is it inappropriate for a company? I don't see any issues. You can view a company as a mother too.

One of the reasons a country has feminine gender is the association with the mother land (ie. one's native country).

Not all countries have feminine gender, just check https://en.wikipedia.org/wiki/Fatherland
Post reply on HN