Among other reasons, not encrypting traffic gives an opportunity for bad actors to replace content in transit to your end users when your end users are on compromised connections, such as rogue "free" wifi networks in airports or coffee shops, or even legitimate networks which have in some way been compromised, e.g. the ISPs of the world who decide to inject other content e.g. their own ads into unencrypted traffic.
The next question is usually "what could they possibly do, change a few pictures?"
They could inject malicious payloads, and for all your users would know, it would appear to them that it came from your site.
> I can't use LetsEncrypt with my hosting provider
Consider switching. For a static site, consider Gitlab; they do a good job of permitting LetsEncrypt.
---
I sincerely appreciate the question, though. I have marketing people ask me this question all the time in private who hesitate to do so in public because quite a few security types berate them for not doing something "obviously" more secure. It's not at all obvious to most of the world's web designers and content creators that a static site should be TLS'd until it's framed (heh) in this manner. The fact that you asked brings about a massive educational moment.
Anyway, consider switching hosts. :)
don't know the answer myself here.. there are good technical reasons, I agree..
but it is a logical fact that if google search was always 100%, there would be no need for adwords and site ads...
I think we can safely say that this would be a very weird way to go about earning a few bucks through CA investments.
[1]: https://w3techs.com/technologies/history_overview/ssl_certif...
[2]: http://pki.goog/
The Internet is not a safe place. We should aim for HTTPS EVERYWHERE.
I think that's a bit sensationalist.
When I popped my SIM into my iPhone it forced me to download a configuration profile with a self-signed Vodafone cert, which means they can mitm any connection. I think this is required by the government so they can block adult websites by default? (I've also seen torrent websites also fail silently with misleading "server not found" errors)
I haven't looked into if they're doing the filtering via DNS or mitm, but I avoid the censorship by connecting to a vpn.
The filtering in the UK is by inspecting HTTP requests, so when a single image on wikipedia.org was blocked, every request to Wikipedia ended up going through each ISPs hidden proxy. [3]
According to [2], HTTPS sites aren't filtered -- but it references a page from 2004. I suspect HTTPS sites are now simply blocked outright at either DNS or IP level, but I don't have a way to verify this, and can't find any details.
[1] https://wiki.openrightsgroup.org/wiki/Internet_censorship
[3] https://en.wikipedia.org/wiki/Child_abuse_image_content_list...
[2] https://wiki.openrightsgroup.org/wiki/Cleanfeed#cite_note-LI...
Correct me if I'm wrong but I'm pretty sure this enables complete MITM by Vodafone when using cellular network.
http://imgur.com/b0il5xb http://imgur.com/3mw5ZGZ http://imgur.com/6ehhfuZ
The "server not found" errors sound like DNS blocking, which they can do without MITM.
Is there any solution other than totally killing HTTP that protects from HTTPS stripping attacks? HSTS won't protect first visit and STS preload lists can only be so large.
For example, if you're using a ccTLD for the domain, or if it's a generic-TLD and you declare a country in Google Webmaster Tools, that will be a much stronger weighting.
Of course, if that's wrong I'd love to know!
They're not as easy to get away from as you think.
You should think about https for sites like yours the way you think about vaccines. SSL everywhere makes everyone safer, even though it doesn't have a tremendous impact on your own site.
Also, shameless plug, if you want really easy SSL you can use our new startup: https://fly.io. I'm not sure what country you're in, but we have a bunch of servers all over to help make it fast. :)
You can email me if you want to avoid cluttering HN: mrkurt at gmail.
The second is more moral. Making https the default means more and more of the web will be encrypted and authenticated. This is a good thing.