Most arguments are BS but still keep popping up:
- heavy on the CPU (not with anything after 2006)
- hard to setup (not with LE + ACME)
- I don't process information (that doesn't matter/is not the reason, DPI, MITM come to mind)
- browsers can't handle it (lies, browsers handle it fine, unless you're using a browser from <2010)
Better yet: even if the resource/browser stuff were relevant, you can still leave http up and add https as an option.
To be fair, a lot of Jason Scott's audience is people who might choose to use ancient browsers on obsolete platforms.
Again, people might come up with the argument that it's their own problem if they get abused, but also that is just not the reality we live in; any compromised system can (and will most of the time) be used to infect/compromise/attack other systems.
And if you don't want to exploit the browser or the hardware, you can still simply inject a self-refreshing iframe in to the plain text html stream and have that z80 act like a (slow) proxy so you can do things that will point to that Z80 being the 'origin'.
Everybody assumes that 'simpler' or 'reduced' systems are always safer, but as soon as you deal with external interfaces and the outside world, that goes out the window. Lynx was thought to have less of an attack surface because it just did basic text-based browsing with HTML and not much else. Turns out that wasn't the case either.
Ok, I guess that explains downvote to my post. I was just wondering. Cause now we can get free SSL with let's encrypt. And since traffic and be hijacked and modified, it just seems to make sense to have a site that serves text files to have ssl.
this comment mentions their provider inserts ads in non-https traffic.