top | item 46471193

(no title)

ryanisnan | 1 month ago

[flagged]

discuss

order

cogman10|1 month ago

Why? What benefit would https provide over http when visiting a pure information (and I'm guessing statically generated) website?

ryanisnan|1 month ago

Great question. People answered already, but, yeah, basically what they said.

For hobby sites, you could argue (I think the argument is still weak), about the MITM threat being low enough to not be worth doing something, but this is a security blog.

Security blogs matter, because people follow their guidance. This makes them a potentially attractive target for some groups of people.

fordsmith|1 month ago

If you are on a public network without using a VPN you open yourself up to MITM to inject something malicious

Alupis|1 month ago

It is a valid thing to point out, when implementing https on gkh's site would take all of 15 minutes to set up (let's encrypt or cloudflare or whatever you wish).

Things should be https by default these days. There's zero downside anymore.

bqmjjx0kac|1 month ago

Confidentiality, integrity, and authenticity :)