110 karma · joined September 25, 2009
I guess people could do self signed certs that expire in "100 years" but you're right, even installing those can be super painful, and people may not go that far. Of course, initially what people will do is "nothing" and just let the insecure message appear, since it doesn't actually block any functionality seemingly...
In the long term you'd have to "hope" the whole web transitions to https and just rewrite the url's to https, or cache them locally or proxy serve them locally. HTH.
I'll admit when I first heard of them flagging HTTP password fields, my instinct was to write a little javascript to "mimic" password input field behavior (and store the real password away somewhere else, then at submit time, it sends in the correct data). But if it's just a tiny warning on the url bar, meh, not sure if I care...
Also note that https://letsencrypt.org appears to offer free CA certs.
mydomainname.inet2.org
or what not. You can have any domain name you want including ones whose .com and .org and .net are already taken LOL. Great for side projects, free, blah blah...
digitalocean is being attacked on all sides, interesting. Hard to believe that giant AWS is trying to imitate one of its upstart competitors...
VLC also might be "more robust" (in terms of accomodating for file corruption) than your browsers' player, might provide a more "stable" experience cross browsers, or allow things like "convert that video file for me in the browser to images and show me those instead" etc. FWIW.