But even when you want to let people connect without SNI, there is no reason to skimp on security. How about sending people with bad browsers to a different port per site?
You can't do that for the very reason SNI exists. All you've got is the beginning of an SSL handshake on your single IP; you don't know what host they want yet, so you neither know what port to redirect to nor what certificate to serve.
And even if they bookmark the https, it keeps working.
And if they have something like 'https everywhere', then they're not using an obsolete version of IE.
The only failure point is if they click an https link by a third party.
Which protocol the form is submitted via is only half the security issue. The form itself needs to be served over https also to avoid a MITM attack on the destination of the form submission.
But yes, clicking an https link directly would cause issues.
[1] http://www.namecheap.com/ssl-certificates/comodo/positivessl...
You just have to be able to receive email to webmaster@yourdomain.tld for that to work.
GoDaddy is the cheapest, but I hate them. Use Namecheap.
> Class 1 certificates are limited to client and server certificates, whereas the later is restricted in its usage for non-commercial purpose only. Subscribers MUST upgrade to Class 2 or higher level for any domain and site of commercial nature
Class 1 is "StartSSL Free", and Class 2 is "StartSSL Verified" which costs $59.90.
It's bad practice to not use a secure login, because anyone who is sniffing HTTP traffic can see your Uptime Robot username and password in plaintext.
This might not be that bad for this website, but keep in mind how many people use the same email/password for other services, or their email.
you should be using a password manager and have unique for every service.