Hacker News new | ask | show | jobs
by kspacewalk2 2182 days ago
Websites marked "insecure" are still fully accessible.
2 comments

Not always. You may also end up with having incompatible set of ciphers (happened to me).

"Get off my Internet lawn if you can't be up to date" is what we're saying and I just do wonder whether we haven't exchanged too much of accessibility for too little of security.

Not always. Sometimes the browser presents a full-page response to the effect that the site is dangerous at which point, even if it's a harmless site, the non-savvy user will leave. Blanket HTTPS/SSL + Letsencrypt is a disaster.
This only happens if the site used to be HTTPS and no longer has a certificate or the site has long-lasting HSTS.