TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Securing Web Sites Made Them Less Accessible

33 pointsby phil2944 months ago

6 comments

yjftsjthsd-h4 months ago
I was under the impression that you <i>can</i> MITM HTTPS, it just requires the client to trust the proxy (by installing its CA). It&#x27;s mostly used in corporate environments for monitoring &amp; blocking, but it should work for caching proxies too.
评论 #42632054 未加载
评论 #42633149 未加载
评论 #42631960 未加载
graemep4 months ago
This is a common pattern in the development of the web now. The people pushing development are focused on profitable users. People in rural areas of third world countries are not a priority. Disabled users will get the legal minimum accommodation. People with older hardware are usually not commercially important - cheaper tog et rid of them.
ipdashc4 months ago
Ironically for what seems to be an article about webpage performance, this site runs horribly on my phone (Android, Firefox) - something is broken with the scroll, it&#x27;s choppy and unusable. Anyone else?
评论 #42632007 未加载
评论 #42632031 未加载
superkuh4 months ago
This is part of why HTTP+HTTPS still has a place for non-commercial non-institutional just for fun&#x2F;education websites. HTTP+HTTPS is also significantly less fragile than HTTPS-only over any years+ long timescales. Eventually even the tool keeping your CA TLS cert up to date itself will stop working or the root cert will expire, etc. HTTP+HTTPS means the site keeps being accessible. If the threat model allows it, it&#x27;s better.
评论 #42637350 未加载
AnonC4 months ago
Needs (2018) in the title.
fuzzfactor4 months ago
I think it could be restated:<p>Making websites less accessible didn&#x27;t have the miraculous improvement in security that people were wishing for.<p>With things other than just HTTPS adding up to discourage huge percentages of users the way it never used to be.<p>Now if someone can capture a fraction of a percent of the increasingly excluded users, it would be a bonanza.<p>You know, the millions of users that virtually <i>nobody</i> is addressing any more, as the competition to further exclude more visitors ratchets up to encompass more and more formerly mainstream traffic. By the millions at a time. It adds up after a while.<p>Think of the opportunities there used to be.<p>For people that want to have outreach from their website, the delivery to the web as a whole has never been less complete by default.<p>And nobody who can do anything about it can measure what they can&#x27;t see, and they can&#x27;t see it because they have their hands full with trying to squeeze the most out of the diminishing pickings that do make it onto their radar. Any which are not fully harvested already, that is.