https://www.troyhunt.com/heres-why-your-static-website-needs...
The same website to my surprise has an article on why this is faulty reasoning.
https://www.troyhunt.com/heres-why-your-static-website-needs...
The same website to my surprise has an article on why this is faulty reasoning.
If I set up a purely static HTTP-only site in 1998, it would still work with today's browsers, more than 20 years later.
If I set up a purely static HTTPS-only site in 1998, and didn't follow the upgrade treadmill, it would have stopped working for modern browsers some time ago.
Of course, migrating to even a raspberry Pi would be a net performance and perf/watt improvement.
Irrelevant. Low traffic static website.
> at which point you cannot postpone the kernel update anymore because you need the new device drivers, etc. etc
Irrelevant as I didn't upgrade the hardware
>You also don't want to stop updating your HTTP server, CVEs get discovered quite frequently
it's a server for serving a single static page from 1998, nothing bad will happen if that machine is compromised, well, nothing worse that what could be done for not having HTTPs
Here's one: the server has a remote code execution vulnerability, which is exploited to gain root permissions, and your server is serving child porn. The cops are knocking on your door.
Granted, this isn't a pro-HTTPS argument, but you do need to keep your stuff updated, even if it is only a static site.
Having to set up a "certificate" for that would be an unacceptable burden.
Have you ever posted a link to your site anywhere? Imagine you sent me a post card saying "Come to my beach to look at my cool sandcastle" and then when I got there the sandcastle was actually a robot that stole my credit card.
You could say that it wasn't your fault - somebody broke into your private beach and replaced the sandcastle.
But I would probably still blame you for not securing the area and double-checking the contents before inviting people. Even if I didn't blame you, I probably wouldn't respond to another invitation.
What kind of moron shows up to see a sandcastle and doesn't think twice about handing over their credit card?
Likewise, if I go to a website and serves up malware, you don't know it is stealing from you.
I like this. Post-cards are a better analogy for plain http than the sand castle.
Of course postcards are not "secure": everybody can read them, and you can trivially impersonate somebody else sending a postcard. Any serious snail mail communication must go via safer channels. Yet, postcards are a very nice thing to have, it would be a shame if they weren't possible. My kids can easily send a postcard to their grandparents, just by themselves. My grandfathers will probably (but nor surely) receive the postcard, and they will recognize who wrote them (but they can never be sure, really), and everybody will be happy.
In the same vein, HTTPS is better than plain HTTP for serious communication, and there's nothing wrong with it. Yet, the existence of HTTP is another fundamental part of the internet, and I make a point of using it as much as possible.
Do you propose that anonymous postcards shouldn't exist, and that the post office should only accept letters certified by adults who had identified themselves at the local police station? I would hate that! And for the same reasons I hate a world without http.
> Horseshit. Users must keep themselves safe. Software can't ever do that for you. Users are on their own to ensure they use a quality web client, on a computer they're reasonably sure is well-maintained, over an internet connection that is not run by people who hate them. None of the packets I send out are unsafe, so my site does not need HTTPS.
> None of those things are my problem. If people don't want to see my site with random trash inserted into it, they can choose not to access it through broken and/or compromised networks. If other website operators are concerned about this sort of thing, they are free to use HTTPS, but I have no reason to do so. Encryption should be available to anyone who wants to serve encrypted content, but I have no interest in using it for my website. It's a shame that people are using web browsers (note: not my website, but BROWSERS) as attack vectors. The legions of browser programmers employed by Mozilla, Google, Apple, and Microsoft should do something about that. It's not my flaw to fix, because it's a problem with the clients. My site does not need HTTPS.
> Earlier you recommended letsencrypt, and now suddenly you want me to pick a competent certificate authority? The only reason they didn't leak my info already is because my site does not need HTTPS.
> Obviously my site does not display ads; as has [been pointed out][https://news.ycombinator.com/item?id=14666391], It does not even appear to be monetized. This is because I have a real job and the entire web ad industry can fuck itself off a cliff. So, while mixed-content warnings are pretty obnoxious, my site does not need HTTPS.
While I like n-gate's no-bullshit attitude, he seriously needs to check his privileges.
That part about the web ad industry is entirely correct.