Ask HN: Why are so few links posted as https?
In the comments too most people still post http. Ex: The Wikipedia links everyone seems to love.
Is this just because of old habits or do people use plugins that force https in the background?
In the comments too most people still post http. Ex: The Wikipedia links everyone seems to love.
Is this just because of old habits or do people use plugins that force https in the background?
Just check if the HTTP and HTTPS site returns near identical results (e.g. same title, response code, etc) then link to the HTTPS version by default.
A lot of links that get posted are directly taken (ultimately) from search engine results. Someone will search, view the page, then copy/paste it to others.
I wonder if users can be motivated to do the checking themselves when they post the link.
While it's possible to serve completely different pages and sites on https vs http, it's rare in practice, and would be reasonable to penalize.
Did other sites observe the same https boost recently ?
So unless the site in question is set up to redirect http requests to https, most links will be http.
I wonder if browsers should always try https first if no protocol is specified? But then as has been pointed out before on here, there's no guarantee that the http and https versions of the same url will have the same content.
I'll have to look into HTTPS Everywhere. Thanks for the recommendation.
I believe HTTP Nowhere is similar to HTTPS Everywhere, but it "fails closed" - if there isn't an HTTPS version of a site, HTTP Nowhere just doesn't show you that site.
I really hope we one day get to a world where it's feasible to have HTTP Nowhere on by default. There are a shocking number of sites which don't support HTTPS, probably because they are suffering some misapprehension about the overhead it adds. Amazon does a bizarre thing where they bounce you back and forth between HTTP and HTTPS depending on how much information about you that they feel a page reveals. It's quite an unstable situation for such a high value target. I wouldn't be surprised if there are a number of spearphishing and MITM attacks that take advantage of Amazon's cavalier attitude towards its customers' safety and privacy.
I guess I considered it more aspirational than declarative. "Revolution Now!", "HTTPS Everywhere!", etc. :)
HTTP Nowhere looks like it takes a much harder line, which I hope will someday be practical for general usage.
Also if all traffic was protected, attackers wouldn't know which one is worth hacking; now it's still quite obvious.