The whole video is great, but particularly this: https://www.youtube.com/watch?v=_BNIkw4Ao9w&t=1063s
https://doesmysiteneedhttps.com/
There are a lot of arguments about why, even non-secret data connections need encryption. The first and most obvious is that not doing so immediately puts a target on the encrypted data.
By no means an expert but to me it seems like an oversight not to.
HTTPS is secure -> a bug made 2.6% of all certificates less secure -> that's why we shouldn't use HTTPS?
I'm quite confused how that holds logically. You can either argue HTTPS is fundamentally not secure or is irrelevant; or regret that there was a bug but support using HTTPS
That being said:
> Devices likely to be affected by the certificate expiry are those that don’t get updated regularly, like embedded systems that are designed not to automatically update or smartphones running years-old software releases. Users running older versions of macOS 2016 and Windows XP (with Service Pack 3) are likely to face issues, along with clients dependent on OpenSSL 1.0.2 or earlier, and older PlayStations that haven’t been upgraded to newer firmware.
Still not convinced we can claim HTTPS should not be used in the general, or in this particular, case.
The point is I see no evidence why HTTP is better for viewability than HTTPS. I showed there are cases where it’s not. You showed there are cases where it’s irrelevant. But the point remains… when is it worse and is it enough to sacrifice the security benefits?
When browser refuses due to invalid cert. Used to be a thing. Do correct me if it is still not.
> the security benefits?
There are no security benefits for such a site.