This is really going to create an additional layer of inconvenience for people who just want to drop some html documents in an ftp folder and be done with it.
This is really going to create an additional layer of inconvenience for people who just want to drop some html documents in an ftp folder and be done with it.
So I was reading your blog and am particularly concerned about the crypto miner present on the page. Care to explain this to me? Hint: MITM due to insecure context and the miner isn't coming from you but as a user, I'm going to blame you because it happens on your insecure blog page.
Both my personal static site and my "literally only I can use it I've disabled user registration" file host use https. I can think of no good reason not to - to which people always link me that stupid anti-https n-gate article. The same site where the owner links to a Patreon account that I cannot verify is them and not a malicious actor looking to get donations from readers of the site. They also link to a Twitter account that may or may not be them.
And people that _don't_ understand cyber security will have no context for what "not secure" means, and may needlessly avoid a variety of HTTP static-HTML sites, where these security issues aren't that great a concern.
Preventing MitM attacks is the only thing I can think of.
This is not a theoretical vulnerability. Comcast routinely adds stuff to unencrypted web pages.
You don't have to wonder all that hard given how publicly Google has discussed their stance on this. They have been using their leverage to try to force SSL usage for some time, including adversely affecting search rankings for sites that don't use it. They have clearly articulated many times they think SSL everywhere is important for the web, and they have the leverage in search/browser marketshare to try to make this a reality.
> https://security.googleblog.com/2014/08/https-as-ranking-sig...
The Google IO talk for Google's desire for "HTTPS everywhere"
> https://www.youtube.com/watch?v=cBhZ6S0PFCY&utm_source=wmx_b...
For what its worth, most metrics show a significant jump in SSL usage in 2016/17 following the announcement that it could adversely affect search rankings, although who knows if the two are related.
In a way, it's a little like a public health argument. You might not be worried about measles but you should still be vaccinated for the sake of the herd.
"I'm lazy, so I don't want to set up encryption on my website, but please don't tell my site visitors. They don't need to know"
Good education >> Browser gimmicks.
Also I get a huge red alert when I follow that link. Seems like chrome is doing a good job telling people it isn't secure.