FAQ:
1. Why does neverssl.com use Javascript to redirect to a random subdomain?
Over the last year users reported that some networks aggressively cache the fake DNS and pages they use for wifi capture. Neverssl.com now works around this generating a request to a random subdomain - this will bust any DNS cache, and any HTTP cache. It also means that if your browser or ISP caches the Neverssl.com page itself, that's fine.
2. Is NeverSSL.com tracking you or anything like that?
Normal S3 access logging is enabled, so I have a record of every IP address that accessed NeverSSL.com. I aggregate this information by AS number (ISP basically) to "rank" the networks that get the most usage ... this helps me figure out which networks are most broken. I occasionally forward this aggregated data to those network operators to encourage them to fix wifi capture. There's no other tracking, but you are trusting me on that. I am a founding director of Digital Rights Ireland, we sue governments and win for better user privacy.
3. Can I put ads on NeverSSL.com?
I thought about this, but I think it'd degrade the experience too much. I am thinking of maybe putting some rotating art, or inspiring poems, something to add a bit of soul to our day. Ideas welcome!
4. Shouldn't I use example.com?
I predict that example.com/org/net will all go HTTPS, as they are intended to service as canonical examples of internet standards.
5. What happens if NeverSSL.com gets pwned?
I don't understand this risk; it's not setting cookies, there's no passwords, or any personal information.