TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

WordPress.com turns on HTTPS encryption for all websites

447 pointsby jblzabout 9 years ago

24 comments

dankohn1about 9 years ago
Kudos to the Let&#x27;s Encrypt and Wordpress teams. This is what the future looks like. Every webpage needs to be encrypted, and http (as opposed to https) needs to go the way of telnet (as compared to ssh).<p>What&#x27;s particularly great is that there is no configuration of any kind for Wordpress authors or their readers. Like they have done, we need to always default to secure.
评论 #11459126 未加载
评论 #11460409 未加载
评论 #11457078 未加载
评论 #11459652 未加载
评论 #11460834 未加载
评论 #11459250 未加载
评论 #11457510 未加载
kyledrakeabout 9 years ago
Not to say this is a bad thing, but I&#x27;m sure Wordpress just broke a lot of links on their user&#x27;s sites. For example, any embedded images from other servers not using HTTPS means that they won&#x27;t load anymore due to browser policies, essentially breaking the links. It also means that any embedded images&#x2F;videos&#x2F;etc. will only work if the remote server has HTTPS. Again, not a bad thing, but it&#x27;s pretty painful to have to deal with this with a lot of users that aren&#x27;t experts on HTTP, and I&#x27;m sure it&#x27;s a similar story at Wordpress.<p>I can flip the switch for default HTTPS on Neocities in a day. The hard part is figuring out how to not break user&#x27;s sites in that process. Ideas welcome.
评论 #11457164 未加载
评论 #11457215 未加载
评论 #11457717 未加载
评论 #11457518 未加载
评论 #11457131 未加载
评论 #11457117 未加载
pfgabout 9 years ago
Original announcement:<p><a href="https:&#x2F;&#x2F;en.blog.wordpress.com&#x2F;2016&#x2F;04&#x2F;08&#x2F;https-everywhere-encryption-for-all-wordpress-com-sites&#x2F;" rel="nofollow">https:&#x2F;&#x2F;en.blog.wordpress.com&#x2F;2016&#x2F;04&#x2F;08&#x2F;https-everywhere-en...</a>
wfunctionabout 9 years ago
Not relevant to the WordPress part, but can someone explain to me why websites like eBay don&#x27;t run on HTTPS except during login? Doesn&#x27;t that allow any sniffer to steal your authentication cookies?
评论 #11457893 未加载
评论 #11457872 未加载
评论 #11459683 未加载
pred_about 9 years ago
Meanwhile, the chromium preload list just passed 10.000 domains. Things are moving forwards.<p><a href="https:&#x2F;&#x2F;twitter.com&#x2F;lgarron&#x2F;status&#x2F;718242465782853633" rel="nofollow">https:&#x2F;&#x2F;twitter.com&#x2F;lgarron&#x2F;status&#x2F;718242465782853633</a>
评论 #11461271 未加载
geostyxabout 9 years ago
Awesome to see stuff like this. LetsEncrypt is really doing a great service to make the Internet a better place.
simonwabout 9 years ago
WordPress.com illustrates an interesting challenge in supporting SSL if you allow people to use subdomains on your service:<p><a href="https:&#x2F;&#x2F;bestcrabrestaurantsinportland.wordpress.com&#x2F;" rel="nofollow">https:&#x2F;&#x2F;bestcrabrestaurantsinportland.wordpress.com&#x2F;</a> works fine<p><a href="https:&#x2F;&#x2F;www.bestcrabrestaurantsinportland.wordpress.com&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.bestcrabrestaurantsinportland.wordpress.com&#x2F;</a> displays a certificate warning<p>Unfortunately I don&#x27;t think there&#x27;s a good solution for this. Humans are gonna www- things.
评论 #11458060 未加载
评论 #11460372 未加载
评论 #11458093 未加载
评论 #11457662 未加载
评论 #11457882 未加载
dredmorbiusabout 9 years ago
This is great news. All the more so as there is a <i>tremendous</i> amount of high-quality content under the Wordpress.com domain, something I chanced on while seeking out signs of intelligent life on the Internet.<p><a href="https:&#x2F;&#x2F;www.reddit.com&#x2F;r&#x2F;dredmorbius&#x2F;comments&#x2F;3hp41w&#x2F;tracking_the_conversation_fp_global_100_thinkers&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.reddit.com&#x2F;r&#x2F;dredmorbius&#x2F;comments&#x2F;3hp41w&#x2F;trackin...</a>
rogerbinnsabout 9 years ago
Is anyone providing a certificate solution for LAN deployed devices&#x2F;software where there isn&#x27;t a stable name, or for that matter an administrator?<p><a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=11457567" rel="nofollow">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=11457567</a>
hisingabout 9 years ago
I think this is awesome news. Hopefully we will see Chrome starting marking http only sites as non-secure and Apples App Transport Security (ATS) forcing people to switch to https all over the web within a year or two.<p><a href="https:&#x2F;&#x2F;www.chromium.org&#x2F;Home&#x2F;chromium-security&#x2F;marking-http-as-non-secure" rel="nofollow">https:&#x2F;&#x2F;www.chromium.org&#x2F;Home&#x2F;chromium-security&#x2F;marking-http...</a> <a href="https:&#x2F;&#x2F;developer.apple.com&#x2F;library&#x2F;ios&#x2F;releasenotes&#x2F;General&#x2F;WhatsNewIniOS&#x2F;Articles&#x2F;iOS9.html#&#x2F;&#x2F;apple_ref&#x2F;doc&#x2F;uid&#x2F;TP40016198-SW14" rel="nofollow">https:&#x2F;&#x2F;developer.apple.com&#x2F;library&#x2F;ios&#x2F;releasenotes&#x2F;General...</a>
iimpactabout 9 years ago
I would recommend the HTTPS everywhere extensions for your fav. browser. It forces all web-pages to be loaded using HTTPS (if available).<p><a href="https:&#x2F;&#x2F;www.eff.org&#x2F;HTTPS-everywhere" rel="nofollow">https:&#x2F;&#x2F;www.eff.org&#x2F;HTTPS-everywhere</a>
评论 #11460918 未加载
评论 #11458899 未加载
anarcatabout 9 years ago
I wonder how they work around Let&#x27;s Encrypt rate-limiting?
评论 #11458199 未加载
dogweatherabout 9 years ago
A little on-topic hype if allowed: free &quot;HTTPS Everywhere&quot; monitoring <a href="https:&#x2F;&#x2F;nonstop.qa" rel="nofollow">https:&#x2F;&#x2F;nonstop.qa</a>. Hacker News passes with flying colors:<p><a href="https:&#x2F;&#x2F;nonstop.qa&#x2F;projects&#x2F;387-hacker-news" rel="nofollow">https:&#x2F;&#x2F;nonstop.qa&#x2F;projects&#x2F;387-hacker-news</a><p>(Free because I&#x27;m applying the GitHub model: free public projects, will eventually charge for private ones.)
teekertabout 9 years ago
Let&#x27;s encrypt is great, but I&#x27;m still running into people that have Chrome on WinXP or even IE8. It&#x27;s crazy, I know. They did promise to start supporting both o XP because it had something to do with an intermediate cert somewhere. They didn&#x27;t deliver on that promise. I don&#x27;t blame them.<p>By the way, the cert on Wordpress.com is issued by GoDaddy, all the examples I could come up with are also. Guess it&#x27;s a roll out process.
评论 #11457335 未加载
评论 #11457216 未加载
ikeboyabout 9 years ago
Great. Tumblr enabled it earlier this year as well.
评论 #11460364 未加载
brainpoolabout 9 years ago
Let&#x27;s Encrypt is great, but Start SSL has also shaped up considerably. A while back their process and the GUI was a real stumbling point. Today however it is a breeze to get it going. (Disclaimer: I am in no way affiliated with Start SSL)
评论 #11483896 未加载
RawInfoSecabout 9 years ago
While this helps *.wordpress.com users or custom domains using the wordpress.com back end, it&#x27;s going to cause a ruckus with self hosted ones.<p>Neither WordPress or LetsEncrypt has any way to modify global server setting on any shared hosting environment. Slapping in an SSL certificate doesn&#x27;t make a site secure, properly configuring the services that use the cert is what makes it secure.<p>GoDaddy isn&#x27;t going to let Company Xyz rebuild Apache or configure cyphers server-wide...<p>In the end, while this is a move in the right direction, I fear it will give false confidence to many web providers that don&#x27;t have enterprise experience with security fundamentals.
评论 #11458932 未加载
评论 #11460379 未加载
vram22about 9 years ago
Google&#x27;s Blogger is moving to https too, over time, my dashboard shows.
ne01about 9 years ago
I wonder if they bundle multiple domains in one certificate?
mulokaabout 9 years ago
This is awesome news.<p>I wonder if Squarespace will follow suit in this endeavor.
评论 #11458891 未加载
billhendricksjrabout 9 years ago
Squarespace needs to follow suit
评论 #11462480 未加载
upbeatlinuxabout 9 years ago
12+ years in the making.
chinathrowabout 9 years ago
Nice.<p>However, they could have shelved out a couply of hundred of bucks for a wildcard cert before.
评论 #11457153 未加载
评论 #11457174 未加载
frugalmailabout 9 years ago
Wordpress is still a security nightmare.<p>PHP, mostly dyanmic everything, unmoderated cesspool of plugins, themes, etc... where you just drop code, predictable URLs and pages to brute force, I could go on...