top | item 37714832

(no title)

wyuenho | 2 years ago

We seriously need to have a new HN policy that requires every link posted to be HTTPS link

discuss

order

PhilipRoman|2 years ago

Why? There are plenty of older useful sites which work just fine over HTTP. If you mean for cases where https is supported, but link is http - I agree.

appplication|2 years ago

Honest question: what is the consequence of visiting an HTTP link rather than HTTPS for a site where my interaction is read only? Is there some security issue? Or is it privacy concerns.

uobytx2|2 years ago

There is a security issue and a privacy issue.

The privacy issue is that your local WiFi provider, direct isp, and all the intermediate isps can see not only which site you visit, but all your activity within that site (like which pages you visit or things you download).

The security part is that any of those who can view can also do a “man in the middle” attack. Comcast could decide to send you a different version of the website that was more favorable to their company, or inject ads (ISPs have been known to inject ads on sites they don’t own before https was big).

A hacker could send you a version that gets you to download malware by replacing content or links. They can see and effect everything you do and see in such a site if they can intercept your request.

up2isomorphism|2 years ago

After reading something on concurrent algorithms you come up with this irrelevant observation?

Also, no if an http link is about a good concurrent algorithm, I will read it anyways.

anticensor|2 years ago

There still are a few HTTP-only websites.