Live data from Hacker News

HTTPS on NYTimes.com

open.blogs.nytimes.com

71–80 of 167 posts

Re: HTTPS on NYTimes.com

#71

The thing the NYT needs to fix (as of earlier last year) is the fact that you can't cancel your subscription without calling them (which is not the case for signing up). I spent 20 minutes[1] on the phone telling them that yes, I really did want to cancel. It was a worse experience than dealing with Comcast, not least because I felt bad for the poor woman who obviously had some financial incentive to get me to stay o…

So even if you are getting the digital subscription, you still have to phone in to cancel?

Re: HTTPS on NYTimes.com

#72

It's nice to see more news media moving towards using HTTPS. NYTimes now joins a small club, alongside the Guardian and the Washington Post. Here's a dev blog post on the WaPo moving to https: https://developer.washingtonpost.com/pb/blog/post/2015/12/10... And one on the Guardian moving to https: https://www.theguardian.com/info/developer-blog/2016/nov/29/...

Google Chrome is supposed to soon start flashing a "not secure" warning on HTTP sites that have password forms [0]. That's probably at least one motivation for these publisher moves to HTTPS [0] https://security.googleblog.com/2016/09/moving-towards-more-...

What happens with local LAN machines, like the admin webpage for your wireless access point? It's not like they can go HTTPS?

Re: HTTPS on NYTimes.com

#73

It's nice to see more news media moving towards using HTTPS. NYTimes now joins a small club, alongside the Guardian and the Washington Post. Here's a dev blog post on the WaPo moving to https: https://developer.washingtonpost.com/pb/blog/post/2015/12/10... And one on the Guardian moving to https: https://www.theguardian.com/info/developer-blog/2016/nov/29/...

Still waiting for Ars Technica to roll that out (for non subscribers)...

Re: HTTPS on NYTimes.com

#74

The thing the NYT needs to fix (as of earlier last year) is the fact that you can't cancel your subscription without calling them (which is not the case for signing up). I spent 20 minutes[1] on the phone telling them that yes, I really did want to cancel. It was a worse experience than dealing with Comcast, not least because I felt bad for the poor woman who obviously had some financial incentive to get me to stay o…

This is one reason I'm actually a big fan of the fact that Apple News supports news subscriptions in iOS 10 (though of course not everyone supports Apple News's subscriptions stuff, including NYT). It ensures these shenanigans don't happen as much, since the payment goes through Apple, and Apple's subscribe/unsubscribe flows are generally very good because the UX they aim for is very different and independent of the particular subscription.

Re: HTTPS on NYTimes.com

#75
post #53

Interestingly, Certificate Patrol warned me that the certificate at that site changed from a "Domain Validation" to an "Organization Validation" certificate from the same CA. Why did they do that change, and what would be the advantage for them of an OV instead of a DV certificate?

OV are considered more secure than DV due to the higher registration requirements[0]. Additionally a DV certificate is good for a single domain, OV certificates are good for all of that organisation's domains. For example the NYT's certificate is valid for: DNS Name=nytimes.com DNS Name=*.blogs.nytimes.com DNS Name=*.blogs.stg.nytimes.com DNS Name=*.dev.nytimes.com DNS Name=*.nyt.com DNS Name=*.nytimes.com DNS Name=*…

> OV are considered more secure than DV due to the higher registration requirements[0]

Nonsense. OV is no more secure than DV, just more expensive.

Re: HTTPS on NYTimes.com

#76
post #44

It's nice to see more news media moving towards using HTTPS. NYTimes now joins a small club, alongside the Guardian and the Washington Post. Here's a dev blog post on the WaPo moving to https: https://developer.washingtonpost.com/pb/blog/post/2015/12/10... And one on the Guardian moving to https: https://www.theguardian.com/info/developer-blog/2016/nov/29/...

A few more here: https://securethe.news/sites/

Oh, the irony:

  Loading mixed (insecure) display content “http://analytics.freedom.press/piwik.php?idsite=4” on a secure page

Re: HTTPS on NYTimes.com

#77

Earlier quoted context omitted.

Google Chrome is supposed to soon start flashing a "not secure" warning on HTTP sites that have password forms [0]. That's probably at least one motivation for these publisher moves to HTTPS [0] https://security.googleblog.com/2016/09/moving-towards-more-...

What happens with local LAN machines, like the admin webpage for your wireless access point? It's not like they can go HTTPS?

[deleted]

Re: HTTPS on NYTimes.com

#78

The thing the NYT needs to fix (as of earlier last year) is the fact that you can't cancel your subscription without calling them (which is not the case for signing up). I spent 20 minutes[1] on the phone telling them that yes, I really did want to cancel. It was a worse experience than dealing with Comcast, not least because I felt bad for the poor woman who obviously had some financial incentive to get me to stay o…

Ugh, their customer service is terrible. I can understand from a business perspective how they aren't incentivized to make it easier to cancel subscriptions... but I'm a paying customer and have had frequent delivery problems (I like to get the actual paper paper), and the people at the call center are just totally unable to do anything to help.

I suppose that's the irony of declining business... after a while you can't even afford to take good care of your existing customers, which further accelerates the decline.

Re: HTTPS on NYTimes.com

#79

The thing the NYT needs to fix (as of earlier last year) is the fact that you can't cancel your subscription without calling them (which is not the case for signing up). I spent 20 minutes[1] on the phone telling them that yes, I really did want to cancel. It was a worse experience than dealing with Comcast, not least because I felt bad for the poor woman who obviously had some financial incentive to get me to stay o…

When you go to the contact page to get the number to unsubscribe, if you hang out for a few seconds an option to talk to someone over chat eventually pops up. They'll try to keep you, hard sell you on other services, etc. just keep saying you'd like to cancel and they'll eventually do it.

It'd still be nice to have a one-click option, but at least it's a bit easier to do passively than needing to call someone.

Re: HTTPS on NYTimes.com

#80

Earlier quoted context omitted.

Very interesting. That's good to know - thank you. I was going to get a subscription for the first time starting in February. I'll have to reconsider that.

That's what companies fail to consider when they deploy these "retention strategies." Every roadblock you put between me and cancelling is ALSO a roadblock between me and resubscription in the future. I've subscribed and cancelled Hulu+ three or four times when there was a lull in the content. But I'd have no hesitation in signing up again because I remember how hassle free it was to cancel. Contrast that against Log…

Same for me and WoW - I'll start up every expansion, play a couple months, and unsubscribe no sweat. I do it again and again because I know I'm not really "committing" to 15 bucks a month, because it'll be easy to cancel.
Post reply on HN