Bonum Certa Men Certa

Why Your Web Site Should Also Support HTTP (Without 'Secure')

posted by Roy Schestowitz on Dec 02, 2024,
updated Dec 02, 2024

Beach Wheelchair rental sign at local beach Florida, USA.

Secure is good. Secure is definitely desirable. But at what cost? Security isn't a bad word, of course not! In fact, we've all become accustomed to hearing about security breaches. We learned about the importance of security and got used to or came to assume transmissions are encrypted one form or another (usually between us and some remote server; for person-to-person communication that's not good enough).

The unavoidable tradeoffs are often forgotten and the issue neglected though. Shaming and humiliation of critical thinkers is all too common in this domain. Anything to suppress candid discussion or proper debate...

You see, on the Web, many old devices still exist that cannot handle HTTPS (we wrote a lot about this matter in the distant past), do not have the latest version and/or protocol (this probably cannot be overcome either, as there's a long chain of stale dependencies), or are wired to handle authoritative domains (or certificates) long expired, in other words deprecated. For this reason, sites which force everybody to use HTTPS have an inherent accessibility problem.

We're bringing up this issue again because it was mentioned in IRC some hours ago. In the past we insisted that everyone should use HTTP or configure the browser to trust our self-signed certificate (for HTTPS). As browsers 'evolved', however, they made it increasingly hard if not altogether impossible. So we sort of gave up, surrendering to the mess the Web had unfortunately become. Secure transmission of pages or page-related data matters when making online purchases (i.e. credit card numbers - an opportunity for fraud) and using banks (that was originally the purpose or motivation); for everything else HTTP tends to be enough. There are many reasons (at several levels) why HTTPS does very little to protect your privacy when you surf the Web, even if strictly over HTTPS (not limited to JavaScript, trackers, DNS and so on).

Sign in the bushes stating there is handicap access

But let's just set the record straight.

Secure protocols are a good thing, but do not impose that stuff on people who come to your site only to read some articles. You're probably losing more than you're gaining. It's like putting a helmet on when cooking in the kitchen; sure, if might protect you (in some rare circumstances), but it can also get in the way.

If your Web site has HTTPS (by default, as increasingly common these days), then adding HTTP should not be hard. It's a lot simpler - can be done easily in a few minutes - than going the other way around. Depending on your 'webserver' software, the configuration file/s may only need a few additional lines. With a front-end interface it might be just some tickbox.

Let people with old computers, old devices (such as TVs with Internet support), and "old" (or simple) browsers regain access. Don't forget RSS readers, either. Some cannot handle edge cases. The same is true for IRC, but that's a story for another day. If we all use unencrypted E-mail (I encrypt every E-mail message that I can for over 20 years already, but both sender and recipient need to exchange keys), why can't we do the same with Web pages that we visit?

To put it a little more crudely, focus on security where it matters most. Many sites get breached/cracked (data compromised or worse) in spite of adopting HTTPS. It's better to focus on the integrity and security of the server itself rather than pseudo-security associated with packets containing freely- and publicly-available pages.

It would be totally appropriate to speak about these issues from an accessibility perspective. Because, in many ways, that's just what we're dealing with. Most disabilities aren't visible to the naked eye (it's not all stuff such as wheelchair or hearing aid, for instance) and are nevertheless something we must bear in mind to properly cater for everybody. The poor person with an old TV that cannot browse sites with the latest TLS may be just as disadvantaged (at least economically) as many others. IBM might make fun of that person (poor-shaming), but IBM is a eugenics company, not a role model for other companies to idolise and imitate.

Blue disabled sign logo

Other Recent Techrights' Posts

Microsoft XBox Layoffs: Almost 2,000 Layoffs Became "Over 2,000"? (Over 20% of the Staff)
over 20% of staff will be let go, not counting staff that leaves voluntarily
Summer Plans in Techrights and Elsewhere
massive layoffs at Microsoft
 
EPO Presentation Bemoans Misuse of Slop in Decision-Making on Patents and in Classification (Which is Likely Illegal Too)
We habitually mention failed use cases of LLMs on the Web
Mass Layoffs at Microsoft Confirmed, "XBox Hardware Is Dead"
It's possible that over 20% of the staff will be laid off
Links 30/06/2025: Kyrgyzstan vs Media Freedom, Dalai Lama Succession
Links for the day
Gemini Links 30/06/2025: Backend Programs in Gemini and Dynamic Content Without The Scripting
Links for the day
Links 30/06/2025: Zuckerberg’s Tax-Evading Scheme Harms Kids, US Copyright Office Lacks Leadership
Links for the day
Microsoft Isn't Laying Off Tens of Thousands to 'Invest' in Slop ('Hey Hi'), It's Laying Off Tens of Thousands Because It's Running Out of Money (and Willing Lenders)
the layoffs are a sign of the business failing, not "hey hi" (whatever that is) replacing staff
Intel Lays Off 20% of Its Workforce, Microsoft is Doing the Same This Year
Like a yoyo, whatever goes up will come back down
GNU/Linux Rises to New Highs in Angola, Africa in General is Abandoning Windows
Western media barely covers Microsoft layoffs in Africa, but in recent years Microsoft culled the workforce and even shut down entire operations
Destination Geminispace (in the Age of LLM Slop and Slop Images That Infest the Web and Social Control Media)
Geminispace isn't vast, but at least it is - on average - a lot "cleaner"
GNU/Linux Growing in Sierra Leone This Year
Based on what statCounter is seeing, this year there are more and more people there who adopt GNU/Linux
Serial Sloppers Gonna Slop
More sites out there ought to call out the cheaters
Quartz (qz.com) is Spam and a Slopfarm
It used to be OK. Then they fired the staff.
Links 30/06/2025: US Economic Woes, Extreme Heat
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Sunday, June 29, 2025
IRC logs for Sunday, June 29, 2025
Gemini Links 30/06/2025: "The AI Hype" and New AuraGem Ask
Links for the day
Our Desktops Are Not Your Experiments, X is Not an Experiment
Breaking what already worked
Microsoft's Big Lies Regarding This Week's Mass Layoffs Have Already Begun (and They're Already Being Spread by Slopfarms)
Microsoft is the "market leader" in slop
Explaining the Full Story of SLAPPs From Microsoft Staff
For every action there is a reaction, for every attack there will be proportionate consequences
The Openwashing Shills Initiative (OSI) - Part III: IRS and Status of OSI
"They lied to the US IRS and there’s a paper trail"
IBM Red Hat's Dogmatic Fanaticism Under a Thin Veil of "Modernism"
IBM now has the audacity to paint people who don't agree as "nazis"
Microsoft's Share in Guatemala Fell From 97% to 14%
Eventually Microsoft will get stuck in a loop of layoffs, layoffs, and more layoffs
They Made Technology Scary and Taught Us That It's Innocent, Friendly, Even "Social"
Rejection of all this "apps" and "gadgets" and "Smart" (whatever that means!) status quo isn't a rejection of society
The Media is Under Attacks Partly Because There's Little Other (Remaining) Press to Speak in Its Defence
The biggest danger here is that when there's very little press or no "opposition media" left it becomes even easier to crush critics because there aren't many people left to speak about the matter
If Your Web Site is Run by Bots, Eventually Nobody Will 'Read' It Except Bots (People Don't Want to Read Slop)
Eventually people learn from mistakes
Links 29/06/2025: Microsoft Releases False/Fake Benchmarks, "Google Wants You to Watch Ads or Take Surveys to Read Articles"
Links for the day
Links 29/06/2025: Data Breaches and Online Censorship
Links for the day
Gemini Links 29/06/2025: "The Price Of Eggs" and Gemini 3D Tic Tac Toe
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Saturday, June 28, 2025
IRC logs for Saturday, June 28, 2025
The "News" You Saw About Canonical is Misleading, It Made Only 18 Million Dollars Last Year and Barely Paid Any Taxes
Lies are the norm these days...
Pushing Wayland Using Straw Man Arguments
phoronix.com has long promoted the talking point of "Wayland people" (for at least a decade already)
Australia: Windows Fell to All-Time Low, Even Lower Than iOS
There's a good reason why next week there will be so many Microsoft layoffs
Slopwatch: Linuxsecurity, WebProNews, and Google News Boosting Slopfarms as 'News'
People who don't recognise the slopfarms and don't know which sites are fake would struggle to understand what's really going on
Links 28/06/2025: Hardware/GPU Wars, GAFAM Throws Money (Borrowed Cash) at Hopeless Slop Pipe Dream
Links for the day
Gemini Links 28/06/2025: Shellshock and Network UPS Tools
Links for the day
Links 28/06/2025: The Age of Integrity and FreeBSD Foundation Added John Baldwin as Board Member
Links for the day
Fedora 44
IBM now does to Fedora what it did to RHEL
Microsoft Already Shaved Off Costs Anywhere It Could. It Was Not Enough.
Office and Windows aren't "selling" (licences) like they used to
Scheduled Maintenance Next Week
Our community is alive and well
BetaNews: We're Publishing LLM Slop About LLM Slop
Beta version of a slopfarm?
3-Month Updates on Our Complaint to the Solicitors Regulation Authority (SRA)
In short, the complaint remains open, updated, and is advancing
IBM Red States Hat (Project 2025): Our "New Thing" Replaces This "Old Thing"
The new replaces the old. That's how IBM frames it.
Start X
Just because something is old does not mean it is bad
Slopwatch: Linuxsecurity, Google News Slopfarms, and Linux Journal (LJ)
Today we take a quick look at 3 slopfarms
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Friday, June 27, 2025
IRC logs for Friday, June 27, 2025
Links 28/06/2025: "CC Signals" Virtue-Signals to Slop Ponzi Schemes, North Korea Aims for Tourism
Links for the day