Live data from Hacker News

HTTPS on NYTimes.com

open.blogs.nytimes.com

51–60 of 167 posts

Re: HTTPS on NYTimes.com

#51
post #38

Earlier quoted context omitted.

Google Chrome is supposed to soon start flashing a "not secure" warning on HTTP sites that have password forms [0]. That's probably at least one motivation for these publisher moves to HTTPS [0] https://security.googleblog.com/2016/09/moving-towards-more-...

I could have sworn firefox already did this, or maybe that ws just elinks...

In current stable Firefox, you have to manually enable `security.insecure_password.ui.enabled` for that.

The change is to set it on by default.

Re: HTTPS on NYTimes.com

#53
Interestingly, Certificate Patrol warned me that the certificate at that site changed from a "Domain Validation" to an "Organization Validation" certificate from the same CA.

Why did they do that change, and what would be the advantage for them of an OV instead of a DV certificate?

Re: HTTPS on NYTimes.com

#54
post #2

Oh no, this was my go-to site whenever I had to login to public wifi and https wouldn't redirect :(

The options I use are the ones the browsers themselves use:

http://gstatic.com (Chrome uses http://gstatic.com/generate_204 , which returns a 204 No Content)

http://www.msftncsi.com (Windows, desktop and mobile, uses http://www.msftncsi.com/ncsi.txt. NCSI is "Network Connectivity Status Indicator")

http://captive.apple.com (macOS / iOS)

because those are likely to be extraordinarily well-maintained and reliable.

Unfortunately sometimes some captive portals allow just this one site through and not the others. Looking at you, United WiFi, which whitelists gstatic.com, but fortunately not msftncsi.com.

Re: HTTPS on NYTimes.com

#55

Earlier quoted context omitted.

Very interesting. That's good to know - thank you. I was going to get a subscription for the first time starting in February. I'll have to reconsider that.

It left a bad taste in my mouth, for sure. Like I said, that was earlier last[1] year; I make no guarantee that it has not changed for the better. [1] Actually I said "earlier this year", which is incorrect as of Jan 1.

can confirm it still requires a call. its worked on me because i dont want to deal with it and keep putting it off.

Re: HTTPS on NYTimes.com

#56

The thing the NYT needs to fix (as of earlier last year) is the fact that you can't cancel your subscription without calling them (which is not the case for signing up). I spent 20 minutes[1] on the phone telling them that yes, I really did want to cancel. It was a worse experience than dealing with Comcast, not least because I felt bad for the poor woman who obviously had some financial incentive to get me to stay o…

I believe there is a customer service chat online where you can also terminate a subscription. I almost did once, but they gave me a discount that I took. All in 10 minutes while reading HN.

Re: HTTPS on NYTimes.com

#57

The thing the NYT needs to fix (as of earlier last year) is the fact that you can't cancel your subscription without calling them (which is not the case for signing up). I spent 20 minutes[1] on the phone telling them that yes, I really did want to cancel. It was a worse experience than dealing with Comcast, not least because I felt bad for the poor woman who obviously had some financial incentive to get me to stay o…

Yeah, that's a Comcast-level move, though to be fair, I tried to unsubscribe from The Economist a few years back and it was a nightmare as well [1], so maybe it's just that the news media industry puts all it's eggs in a different basket when it comes to UX.

[1] http://www.economist.com/help/manageprintsubscription#cancel...

Re: HTTPS on NYTimes.com

#58
post #57

The thing the NYT needs to fix (as of earlier last year) is the fact that you can't cancel your subscription without calling them (which is not the case for signing up). I spent 20 minutes[1] on the phone telling them that yes, I really did want to cancel. It was a worse experience than dealing with Comcast, not least because I felt bad for the poor woman who obviously had some financial incentive to get me to stay o…

Yeah, that's a Comcast-level move, though to be fair, I tried to unsubscribe from The Economist a few years back and it was a nightmare as well [1], so maybe it's just that the news media industry puts all it's eggs in a different basket when it comes to UX. [1] http://www.economist.com/help/manageprintsubscription#cancel...

I tell you what, it sure made me wary of signing up for any more news media subscriptions, now or in the future. It seems almost hypocritical to complain about how people don't want to pay for quality news and then treat them like crap when they do (not that I'm ascribing this to any one person or organization).

Re: HTTPS on NYTimes.com

#59

The thing the NYT needs to fix (as of earlier last year) is the fact that you can't cancel your subscription without calling them (which is not the case for signing up). I spent 20 minutes[1] on the phone telling them that yes, I really did want to cancel. It was a worse experience than dealing with Comcast, not least because I felt bad for the poor woman who obviously had some financial incentive to get me to stay o…

Very interesting. That's good to know - thank you. I was going to get a subscription for the first time starting in February. I'll have to reconsider that.

That's what companies fail to consider when they deploy these "retention strategies." Every roadblock you put between me and cancelling is ALSO a roadblock between me and resubscription in the future.

I've subscribed and cancelled Hulu+ three or four times when there was a lull in the content. But I'd have no hesitation in signing up again because I remember how hassle free it was to cancel.

Contrast that against LogMeIn which has the same strategy as NYT by the sounds of it (call to cancel, takes 15+ minutes). When I needed LogMeIn for a new project, I looked around for alternatives instead because I remembered how big of a hassle it was to cancel. Ultimately LogMeIn didn't get my repeat business, not due to the financial cost, but the hassle cost of them.

Plus of course word of mouth like this is hugely damaging for these strategies. I won't be getting a NYT subscription now.

Re: HTTPS on NYTimes.com

#60
post #28

They mention it has been a complex undertaking and not complete yet - does anyone know why they can't just sit a traffic manager in front of everything with SSL offloading? Also does anyone know what the new personalisation features are that they mention being able to offer now HTTPS in place?

According to WaPo's move to HTTPS blog post:

>Ask any developer at a major media organization what the biggest hurdle to HTTPS adoption is, and the answer is always going to be advertising. However, unless you understand the ins-and-outs of how digital advertising is implemented, it’s difficult to see why this presents a challenge.

from https://developer.washingtonpost.com/pb/blog/post/2015/12/10...

Post reply on HN