Also does anyone know what the new personalisation features are that they mention being able to offer now HTTPS in place?
Also does anyone know what the new personalisation features are that they mention being able to offer now HTTPS in place?
>Ask any developer at a major media organization what the biggest hurdle to HTTPS adoption is, and the answer is always going to be advertising. However, unless you understand the ins-and-outs of how digital advertising is implemented, it’s difficult to see why this presents a challenge.
from https://developer.washingtonpost.com/pb/blog/post/2015/12/10...
It's also possible that terminating the SSL and then passing through unsecured traffic lower in the stack is not ideal due to where the different parts of the site are hosted - e.g. passing traffic unsecured back and forth between private DC and public cloud.
Note: All speculation based on having implemented SSL migrations at large media companies.
Also, features that are now available once the HTTPS by default on a website, is the AMP, Notifications, HTTP2 (faster loading) and, of course, the little advantage that Google gives to the HTTPS websites.
Not sure what features the NYT is referencing specifically, but Chrome has certain features [like the Geolocation API][1] disabled for pages loaded over HTTP. See [Deprecating Powerful Features on Insecure Origins][2].
[1]: https://developers.google.com/web/updates/2016/04/geolocatio...
[2]: https://www.chromium.org/Home/chromium-security/deprecating-...
If you don't mind 404ing or breaking a ton of your old content, it's probably not too difficult. But if you're the newspaper of record, it's a big deal that URLs live on and continue to work as expected.
But I think you hit the nail on the head -- being the "newspaper of record" means you want to ensure that all your content displays like it did the day it was published.
We could also set a header forcing the browser to upgrade to secure when the resources are in the same domain.