Earlier quoted context omitted.
That's an archaic and half-valid use, so stretching it to apply to a company makes it pretty much invalid. You could try to convince people to use the word that way, but at present it's just not done. Companies are 'it' or you can talk about the people that make up the company as 'they'.
If you try to dictate how language must be used you're just being ignorant of how she constantly evolves through her use by different speakers. So, there.
Google Will Soon Shame All Websites That Are Unencrypted
331–340 of 369 posts
Re: Google Will Soon Shame All Websites That Are Unencrypted
#332Which is hilarious because the reason I can't switch The New Yorker website to HTTPS is because of ads - which I'm getting from Google DFP which allows non-secure ad assets. In short; Google will penalize me because I use Google. The universe has a sense of humor.
Re: Google Will Soon Shame All Websites That Are Unencrypted
#333Earlier quoted context omitted.
That's an archaic and half-valid use, so stretching it to apply to a company makes it pretty much invalid. You could try to convince people to use the word that way, but at present it's just not done. Companies are 'it' or you can talk about the people that make up the company as 'they'.
If you try to dictate how language must be used you're just being ignorant of how she constantly evolves through her use by different speakers. So, there.
Re: Google Will Soon Shame All Websites That Are Unencrypted
#334Earlier quoted context omitted.
But if you have a child company, wouldn't you expect to associate the parent company with a feminine gender before a masculine gender? That's what I am getting at. An organization has that "motherland" feel in some way.
Not really, no. Motherland is a very specific term that's been ingrained into English most likely because of the close personal relationship between people and their native countries, which would have been Britannia for many English speakers when the language was developing. There isn't really that same deep and universal connection when talking about organizations, so a similar term probably wouldn't develop anytime…
Re: Google Will Soon Shame All Websites That Are Unencrypted
#335Consider this: - Squarespace doesn't support SSL (other than on their ecommerce checkout pages) [1] - Weebly only allows it on their $25/mo business plan [2] - Wordpress.com doesn't support SSL for sites with custom domains [3] - If you've never experienced the process of requesting, purchasing, and then installing an SSL certificate using a hosting control panel like Plesk or cPanel, let me tell you–it's a nightmare…
Re: Google Will Soon Shame All Websites That Are Unencrypted
#336Why do we have to go through this whole SSL certificates thing and can't just have a simple, automatically secure, I-do-nothing-and-my-website-is-secure protocol? Seriously though. If secure is the default from now on, why can't it actually be the default?
Seriously this. I don't see why encryption and website verification have been wrapped up in the same thing (SSL certs). They're two different things. Encryption should be free, automatic and default.
You need a way to verify that the site you're connecting to really is who it claims to be before you can trust even an encrypted connection to that site. Otherwise you don't know whether you just established an encrypted connection to the website, or an encrypted connection to a malicious attacker.
Re: Google Will Soon Shame All Websites That Are Unencrypted
#337Earlier quoted context omitted.
Similarly, Google claimed they would start penalizing websites that showed full-page ads for mobile apps instead of showing you the website. But every single time I try to get to Gmail, or Drive, or Calendar, or any Google service on the web using a mobile device, I'm shown a full page ad for a mobile app. Google has been doing this for years, and it seems like it's also been a year since they said they'd punish all…
The fact is they did penalize themselves for couple of times in history.
Re: Google Will Soon Shame All Websites That Are Unencrypted
#338Earlier quoted context omitted.
buying a certificate and changing it yourself. So it costs minimum price a certificate, and at least one person competent enough. And competence in terms of spending is way more than the certificate. Outsourcing security without knowledge is praying for being abused. So sometimes you are better in terms of costs and efficiency without. And HTTPS cost more for rural users because you cannot cache SSL contents. So in a…
Certificates are free. The required competence is only marginally more than the required competence of setting up a website, and is rapidly dropping to zero more. (And is , if your website is hosted by a third-party service, which is a pretty reasonable approach for the organizations you name.) I don't understand what you mean by "Outsourcing security without knowledge is praying for being abused." From your original…
I do not. It has a cost. If you do not check you have the perfect tool for a MITM.
Then is https more expensive than http?
Of course you idiot. Have you never seen your CPU burn under https? With TLS the load is on the first connection. Meaning it is around x% (x said to be 1 by google) for long sessions IF and only IF you have a costly engineer optimizing your stack. And I know by experience that google cipher suite are sometimes close to be ridicusly weak in order to achieve this. (I saw an RC4 while playing with gmail). And that is servers side. Add the client side.
So what about no "engineer". What about an SSL2.0 cipher suite having RC4 MD5 ... and all the default weak settings recommended you can see on the internet?
Well, the illusion of security is no security. the S of https is for security. Having a tag saying I am secure if any government or criminal organisation can break your ciphering in a matter of seconds is no actual security. And it defeats the purpose of TRUST granted by security.
Then way pay the extra x% of https in this case?
Oh! I just read your last paragraph.
Can someone explain to this person why HTTPS cannot be cached? Oh! It can it : has been sold to Tunisia by MS in 2007, France to lybia circa 2005, China is doing it ... for intercepting and deciphering citizens conversation.
Caching HTTPS is basically doing a Man In The Middle attack. It requires a "joker" certificate nicely given by a root authority. Doing so (as microsoft did) normaly induce "the death penalty" of security firms. MS is alive, hence anyway we cannot trust https ... since snowden revelations.
The proxy would still have to do the handshake anyway to have the https => cpu load.
The premise of security are trust. https nowadays is a costly joke.
For the record operators especially when IP routing goes through shared tunnel of collects (3G) have been traditionnaly using a protocol called WCCP to cache transparently your http content. And 4G is deployed substantially in USA & wealthy European countries, but not everywhere.
So even if you don't have a proxy your operator may.
And if you think all USA is at 1Mb/sec for 50$/months read this http://seclists.org/nanog/2015/Oct/337
Last and least : I worked in an ISP 10 years ago. One of the datacenter was 5% of france global traffic, the electricity used was as much as a city of 40K inhabitants.
It makes internet as an industry the biggest user of fossil energies. According to my approximation we should be around 2%[+1%?] of the global national consumption. Very near transport industry (plane + trucks). And https will not help.
So I see no other arguments for https than being sheeps.
Re: Google Will Soon Shame All Websites That Are Unencrypted
#339Earlier quoted context omitted.
Yeah I'm all for SSL shaming but my personal site with SquareSpace is about to look like shit for me since I'm a web developer. I mean as a web developer it's not going to look good if your portfolio is shown with a security warning. I wonder if SquareSpace is going to finally fix their shit or if I'm going to have to move elsewhere which is going to be a pain (I went with SquareSpace because I didn't want to be asse…
No offense intended with this, but, as a web developer, what the heck are you doing creating your site on SquareSpace? Shouldn't you...I dunno...develop your own web site?
Re: Google Will Soon Shame All Websites That Are Unencrypted
#340Earlier quoted context omitted.
Yeah I'm all for SSL shaming but my personal site with SquareSpace is about to look like shit for me since I'm a web developer. I mean as a web developer it's not going to look good if your portfolio is shown with a security warning. I wonder if SquareSpace is going to finally fix their shit or if I'm going to have to move elsewhere which is going to be a pain (I went with SquareSpace because I didn't want to be asse…
Why not just put your SquareSpace site behind Cloudflare? Then you get free SSL.