Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

This thread illustrates exactly the problem with HTTPS.

The proponents of HTTPS everywhere try to sweep the significant downsides under the rug, whilst others are spreading all kinds of unfounded FUD about HTTPS.

The bottom line is that "your mileage may vary". For some applications, SSL is trivial, and there is no excuse not to do it. For other scenarios it's a nightmare with all kinds of undocumented complications.

I'm currently working on providing SSL for a SaaS service with various client domains on AWS (i.e., with a limited number of IP-addresses). Doable, but far from trivial or inexpensive.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: