Hacker News new | ask | show | jobs
by enzanki_ars 1866 days ago
For a good discussion into why _all_ websites should use HTTPS, I'd highly recommend this article.

https://www.troyhunt.com/heres-why-your-static-website-needs...

Not having your site as HTTPS puts all of your readers at risk. Even US ISPs like that of Comcast use this very same practice to inject warnings into insecure web traffic[0]. And like mentioned in the article, promises from ISPs not to use it for advertisements are just that, promises, and those can be broken in an instant.

[0]: https://gizmodo.com/comcast-to-customer-who-noticed-it-secre...

1 comments

This article is controversial and shows a distorted and incomplete point of view. For example, https sites are more vulnerable to some types of censorship. A CA can censor your site by unilaterally revoking your certificate. It routinely happens already. Promises from CAs not to censor you are just that, promises, and those can be broken in an instant.