Just speaking generally, I found the use of an http: link on this very curious, given that it’s about SSH (and thus encryption in no little part), so I’m guessing you’re not a “Web Developer”. So here’s my advice on the matter: everything on the web should be HTTPS now; nothing should be plain-text HTTP, with zero exceptions.
People still send postcards, where they don't care if people read what's written on it..
ISPs, Comcast in particular, inject ad-loading javascript into HTTP pages.
https://arstechnica.com/tech-policy/2014/09/why-comcasts-jav...
Any ISP is allowed to sniff and manipulate packets, so this isn't just about my ISP -- it's the server's ISP as well as any entities in-between.
Even if I did (assuming that I reasonably could!) change my ISP, that's changing only one of the potentially many hostile actors.
>why wouldn't you use a vpn
That would require me to trust the connection between the VPN and the server.
Plus, then I would need to buy a VPN subscription :) Just serve HTTPS!
A vpn moves any legal situation into a country with different laws.
Your isp knows you visited a certain domain with https. That's a concern.
You just shift the trust around. Now I have to trust the hoster, e.g. OVH instead of my local ISP. Really the best thing you can do is end-to-end encryption, don't send plaintext over the internet.
> Your isp knows you visited a certain domain with https. That's a concern.
How about DNS over HTTPS?
Grandparent said "unforgivable".. sheesh, over the top much?
There tend to be about 0–2 http: entries on the front page. A fairly large fraction of those are old things. http: submissions on domains that support https: (whether or not they redirect to it by default) are very uncommon.