"Since most of the other answers here deal with the downsides of site-wide SSL (mainly performance issues - btw these can easily be mitigated by offloading the SSL termination, either to an SSL proxy box, or an SSL card), I will point out some issues with having only the login page over SSL, then switching to non-SSL:
- The rest of the site is not secured (though this is obvious, sometimes the focus is too much on just the user's password).
- The user's session id must be transmitted in the clear, allowing it to be intercepted and used, and thus enabling the bad guys to impersonate your users. (This is mostly what the Firesheep hubbub was about).
- Because of the previous point, your session cookies cannot be marked with the secure attribute, which means that they can be retrieved in additional ways.
- I have seen sites with login-only-SSL, and of course neglect to include in that the Forgot-password page, the Change-password page, and even the Registration page...
- The switch from SSL to non-SSL is often complicated, can require complex configuration on your webserver, and in many cases will pop up a scary message for your users.
- If it's ONLY the login page, and f.e. there is a link to the login page from your sites home page - what is to guarantee that someone won't spoof/modify/intercept your homepage, and have it point to a different login page?
- Then there is the case where the login page itself is not SSL, but only the SUBMIT is - since that's the only time the password is sent, so that should be safe, right? But in truth that removes from the user the ability to ensure ahead of time that the password is being sent to the correct site, until its too late. (E.g. Bank of America, and many others)."
I imagine top YouTube contributors would be pretty annoyed if their account got hijacked.
I was chatting with a youtube engineer last night and she told me that she does not recall a wide discussion on disabling http fully, I thus submitted a request in youtube's forum and see how it goes.
There are extra complications besides the server setup. For example, it's harder to avoid mixed content errors on HTTPS pages, you couldn't just use the "secure" flag on all cookies and you need to be careful not to send passwords or session data over HTTP. Many sites have login forms on HTTP pages that then send you over to the HTTPS site for example but this isn't secure.
Not saying it has no benefits, but mixing HTTP and HTTPS does have complications.
> I was chatting with a youtube engineer last night and she told me that she does not recall a wide discussion on disabling http fully, I thus submitted a request in youtube's forum and see how it goes.
Great, I'd be interested to know the reason as well.
The pages themselves are so interlinked with account info & access ... that they really shouldn't be loaded without HTTPS. And weird mixes of HTTP and HTTPS are a pain to make work, because browser rightfully block mixed-content and it's way to easy to make security mistakes. Easier to just slap TLS on everything and be done with it.
Don't forget that loading a single page over HTTP gives a perfect entry-point for MITM attacks to redirect to e.g. a faked copy of youtube that steals data.
What downside does HTTPS for everything have for you?
the benefit of having http:
1. corporate proxy can filter youtube
2. we can do content-filter for kids browsing
3. better caching support in proxy
4. much less demanding on hardware, ssl is very cpu intensive etc
1. There are more effective methods.
2. There are more effective methods.
3. Not useful for long-tail and no one wants modified videos.
4. The additional overhead is an insignificant cost, even to YouTube.
Your reasons for wanting HTTP are the same reasons YouTube uses HTTPS. They don't want third-party blocking, tracking, interception, or modification. YouTube is doing what their users want by protecting them.
In 2016, any company that doesn't use HTTPS everywhere is probably incompetent.
when content filtering is mandated(corporate, school, church,etc), they're going to do it anyway, just need more powerful router/firewall/proxy in the middle, if http is available it will ease that to a great deal.
for people needs security, just use https by default, for people perfers to http sometimes, they will have the optional choice, just like what google.com does now.
2. Content filtering can be done in other ways, more effectively. HTTPS does not prevent this.
3. Everyone needs security and privacy.
You don't seem interested in learning, so I'm done trying. Keep believing whatever you want while the entire web moves to HTTPS-only for very obvious reasons.