Talking about certs, nowadays it seems browsers want to make you believe that self signed certs are some diabolical work straight from hell. Using self signed certs with websockets on Firefox is actually nearly impossible [1].
> Targeted users in Turkey and Syria who downloaded Windows applications from official vendor websites including Avast Antivirus, CCleaner, Opera, and 7-Zip were silently redirected to malicious versions by way of injected HTTP redirects. This redirection was possible because official websites for these programs, even though they might have supported HTTPS, directed users to non-HTTPS downloads by default.
[0] https://twitter.com/codelemur/status/1052285395575164929?s=2...
Mind you, HTTPS doesn't mean downloads are safe. Not remotely so. HTTP just means they're way less safe, and if you're on a HTTPS website it definitely should not be serving downloads over HTTP
1: https://developer.mozilla.org/en-US/docs/Web/Security/Secure...
Mozilla: Okay, done.
The Venn Diagram of people who forgo managed hosting with SSL built-in and set up their own servers to host HTML pages on the internet and the people capable of following a guide to configure certbot is a circle.
And what of those who have left their old site (that has no need for TLS) online for years without ever knowing 'insecure' HTTP is being deprecated? I don't think their sites breaking and showing warnings should be acceptable when the security benefits are so marginal.
Let's Encrypt has made installing a cert a 5 minute process, including setting up automated renewals.
Even at lawyer rates ($200/hour), that's still less than a one time $20 "cost".
Look I get it, if I hosted sites on shitty providers and couldn’t change because of corporate BS I would be frustrated too. But “everyone else should change to accommodate my problems” isn’t the right response. It’s the same with crappy SSL middleboxes, I feel for people who have to deal with broken sites because of them but breaking TLS as a workaround can’t be the way forward.