If IPv6 actually gets deployed to the extent that I can have an IPv6-only site without needing IPv4 addresses, and someone solves the SSL signing mess, I'd be happy to use it.
If IPv6 actually gets deployed to the extent that I can have an IPv6-only site without needing IPv4 addresses, and someone solves the SSL signing mess, I'd be happy to use it.
The only scenario where I wouldn't do it is a blog. There's probably no sensitive content there and without SSL you can use the free trier at CloudFlare to HN-proof it.
You can also get alt names on your certificates, so if you want to support IE on XP or Android 2.2 then you can put several domains on the same certificate.
I have no interest in StartSSL, just a happy customer :).
As long as you're not supporting clients running IE on WinXP or other similarly old web browsers, Server Name Indication (where the hostname is included as a part of the handshake) will work and it'll eliminate your need for more than one IP.
It shouldn't be hard and you should have to pay such a premium for something that should just work by default. I helped create a Front-end PaaS a little while back[2] that believed in that philosophy, we worked hard to lower the barrier of entry for most things, including SSL.
The reality is understanding SSL, Encryption and everything involved is still overwhelming for most people. This article helps but we need more services to stop gouging people for doing or trying to do the right thing.
[1] https://www.cloudflare.com/plans [2] https://blog.harp.io/posts/harp-platform-now-public
This is certainly no longer true. $7 for a cert from Namecheap (domain validated).
https://www.namecheap.com/ssl-certificates/geotrust-ssl-cert...