Ask HN: Put my entire website behind ssl?
healpay.com
healpay.com
http://platform.twitter.com/widgets.js vs https://platform.twitter.com/widgets.js
Luckily, we don't use that js, we use:
http://twitter.com/javascripts/blogger.js
and I just checked the certificate behind this and it's valid (I should hope twitter's main cert is valid!):
https://twitter.com/javascripts/blogger.js
and we use the json API:
http://api.twitter.com/statuses/user_timeline/healpay.json?c...
which also happens to have a valid cert:
https://api.twitter.com/statuses/user_timeline/healpay.json?...
So it looks like we're in the clear for this at least :)
It's very interesting to me that when SSL opens up, you immediately feel like confidential information information is going to be passed (which is usually the case).. I didn't think about that before!
The app portion is def. protected by SSL and switches to that context when you hit the login path.
Your last point is interesting too, as we do pull in external resources such as google fonts, jquery (google's CDN), analytics, etc. but have managed to find an SSL version of those URL's too (luckily). I do see this becoming painful for designers moving forward though when they're trying to pull in external resources that lack support for https url's.
All very good points.
Do you think the average user notices the SSL activation bar?