I use HTTPS only. I don't think HTTP is acceptable for anyone let alone a technical blog post. It takes a few minutes, and it prevents me and all your visitors from getting all kinds of MITM injections.
Thanks.
I use HTTPS only. I don't think HTTP is acceptable for anyone let alone a technical blog post. It takes a few minutes, and it prevents me and all your visitors from getting all kinds of MITM injections.
Thanks.
HTTPS on a blog does nothing. It doesn't protect you from anything. I guarantee you're not getting "all kinds of MITM injections" on this block of text. The only reasonable desire I can think of for "HTTPS everywhere" is hiding the content from your ISP but a) they still see the URL so they can get the content if they want it, and b) if you're so worried about that, use a VPN which coincidentally is even better because it will also hide the URL, and most importantly c) it puts the onus on you, the person who wants the thing, instead of hundreds or thousands or tens of thousands of text-only website owners who rightly couldn't care less about HTTPS.
You actually can’t guarantee anything of the sort. BGP hijacks are real.
That's incorrect, a MitM can only reveal the server hostname by inspecting the SNI during the TLS handshake, but the HTTP request, including the URL and headers, is encrypted.
https://en.wikipedia.org/wiki/Server_Name_Indication#Encrypt...
It does nothing now. There used to be ISPs who injected ads into web pages as an additional revenue stream. This stopped being a viable strategy precisely because browsers forced a transition to HTTPS.
Also your ISP doesn't get to see the URL under HTTPS. They get to see the IP address and SNI if not encrypted. This may reveal the blog if the blog is not behind cloudflare etc.
More annoying is the slightly shiny/shaded text that is supposed to highlight something. Who chose this style palette?
Millions of routers are compromised. BGP attacks happen. Anything http stands out as an interesting target for injection.
This position is foolish. It’s not a major ask to enable https.
You cannot browse to sites under any regime and execute code while expecting security to exist.
If you control the IP a domain name points to, you can get a certificate issued. Https might help on a small BGP takeover, but it might very well not.
(This is a general remark, but it goes for a blog post like this as well.)
And the best Windows malware is actually digitally signed.
With static webpages, the concern isn't someone snooping in on what I'm reading. It's someone injecting content, probably malware, into the page. Let's say I have a zero-click exploit for Chrome. What can I do with it? If I just stick it on a page I control, best I can hope for is spamming it all over the web and hoping someone clicks on it. Probably not a lot of impact before it gets patched. If instead, I can wait until some router firmware gets pwned, or an ISP, I can do a mass attack where I make all the vulnerable routers inject my exploit into all non-HTTPS web requests. Much greater exposure.
A long-standing HN guideline. Regardless of how merited the complaint may be.
I don't remember turning it on but it's probable that I did, it's not a default yet but will be come October: https://blog.google/security/https-by-defau/
It could make it less likely for a CA with buggy code to accidentally issue a cert for your domain.