(no title)
harlequinn77 | 3 years ago
The only sensible reason I can think that BOM is not under https is that there are ancient mission critical consuming services somewhere that can't handle the upgrade.
For example: a network of regional flood warning alarms that are pulling flood/rainfall data from a feed on the same url. They could have been built in the early 80s, and cant be upgraded. Ignoring them would risk lives etc etc
Nevertheless there would be other ways to solve that.
can16358p|3 years ago
Even if there was an ancient service that can't handle HTTP, keeping HTTP and adding HTTPS support will do just fine.
cdogl|3 years ago
My guess is that their entire system is so tightly coupled that they can't unpick this without a huge amount of work that requires real developers to stick with it and get around it.
stubish|3 years ago
zsims|3 years ago
dopidopHN|3 years ago
jiggawatts|3 years ago
There. I’ve solved it.
Similarly, a filter based on User Agent would likely also work.