only suggestion: support https...
only suggestion: support https...
I get bothered by it, Chrome doesn't even allow to confirm and proceed at the boom of the warning page anymore, but there is some flag you may disable if you feel safe about all your visits.
Hopefully Google will start flagging ipv4 servers too. And one day block them by default.
So why bother? Just be secure and move on.
Its purpose is to authenticate financial transaction packets, not to be "secure". (Whatever that means.)
It is never worth asking "should I even do https?" The only variation worth considering is "is https enough?" And even then, start with https and then build on top.
> The only variation worth considering is "is https enough?"
Enough for what exactly? Since this charade clearly isn't about security, what exactly is the metric for "enough"?
What sort of definition are you using for security? It's obviously not the standard one.
Sending passwords in the clear vs not is covered on the first day of security 101.
Which you don't have, because you're not doing security. Just buzzwords.
"I don't want other people to know my passwords".
Perhaps you don't understand what HTTPS does. Which is totally fine! Lots of people don't really get it (or even need to). But yelling "buzzwords" for the things you don't understand doesn't make the usefulness go away.
For someone so wrong about this, you're very opinionated! It's quite a dangerous mix. Thankfully, not dangerous to me, so I can just have a little chuckle and move on.
All for the price of about the same amount of work that it took to read this message.
"Https is only for credit cards" is some serious 1990s bullshit.
This may seem inconsequential for static websites without PII, however most browsers consider it important as it reduces the risk for all parties involved when encrypted communication is used and the content providers has taken basic steps for Identity verification.
There are logic flaws with this approach to security imo, but it's the most commonly used technique at the moment.
ISP's are usually serious businesses with reputations and don't hack their own customers.
https://www.simpleanalytics.com/blog/vodafone-deutsche-telek...
In some places and on some networks, MiTMing http traffic for undesirable use-cases is routine.
(It's effectively a "doing business on the Internet" tax. Thankfully not that expensive for small hobby projects now.)
https://www.bitdefender.com/en-us/blog/hotforsecurity/turkis...
Years before that the free certificate authority Let's Encrypt was established (there are now several more), so for most people using https with your website is just configuration, not an extra cost. On top of that some http protocol versions are now https only.
We need https because the modern web browser isn't a trustworthy or secure program. A web browser isn't a sandbox so code can be injected into an insecure http stream to force the browser to compromise the machine it is running on. This is just the state of the internet - there are literal highwaymen in the form of malicious routers and other networking hardware on the internet. https is unfortunately the ony way to ensure the highway for your data is secure and the data arriving to you is trustworthy.
The only way to avoid this is to use a browser like netsurf that eliminates the insecure modernity or dont use the web.
Man in the middle attacks are very real. A good ratio of routers get hacked during manufacture, or have a backdoor that get exploited by other hackers. an http hits make these exploit even easier to execute. Public WiFi are often insecure, https works around that problem (for the most part).
From an attacker perspective, widespread https has become obnoxious, yes.
I was wondering if you would be adding any IDE-like features. I like a few features in Sonic-Pi and noticed a few attempts to make a VS Code plugin for it. (I wish I could contribute myself, but my music production skills are atrocious and I mostly rely on GUI-based software to carry me.)
Congrats on an awesome project! (And you, OP, too!)
I had to regenerate ssl certificate, ovh says it's done but it will probably take some time to take effect.