LFGSS going HTTPS by default

Posted on
  • LFGSS has been available over https for ages. But... only 58% of requests go over https.

    Has anyone got a good reason why it shouldn't be 100%?

    I have lots of good reasons it should be 100%:

    • https means http/2, which means a multi-plexed always on connection
    • https actually speeds the site up, rather than slows it down
    • https makes everything encrypted by default, which is good
    • It's good because it means third parties (like your ISP) cannot inject dodgy adverts and other crap
    • It's good because it means most workplaces cannot track access beyond know the IP you connected to

    What I think may break:

    • Some images on some older posts that are inline and served on http may not show
    • bikely embedded map won't show (as they are http only)

    That's it.

    Everything else will work, and go faster.

    If there are no good objections, I propose to add a redirect from http to https later today.

  • It's a few since I worked server side though but it shouldn't be an issue. HTTP can still be displayed with HTTPS as far as I know, it's down to the browser.

    I use "HTTPS Everywhere" which will always try SSL first

  • Meh... maybe I'll do this the other way around.

    I'll put the redirect in and will see how many people scream and what for :)

  • Doing that now.

  • Done.

    HTTPS is now enabled by default... who has issues?

    (silence, since those who do just got locked out)

    Great, appears to be working well.

  • Post a reply
    • Bold
    • Italics
    • Link
    • Image
    • List
    • Quote
    • code
    • Preview
About

LFGSS going HTTPS by default

Posted by Avatar for Velocio @Velocio

Actions