If your website is still http only, no https...
... are you okay? Do you need help doing archival work? this isn't shade, we just saw the long tail of the web forced offline with the move to https everywhere.
Are you holding on to an http only site for someone who's passed? DM me and I'll help you save a copy some place more durable than a personal or academic server sitting on someone's desk or in a closet. Let's save the remnants of the old web before they go offline entirely.
@aredridel honest question: if the site is a static site, with no moving parts or logins, does it *need* to be https?
My site is https and has been since blacksheep, but it also has logins so is vulnerable to various front-end shenanneans. But for a static site I assume the only way in is via backend tools (ssh, sftp) which use encryption but not *web* encryption.
At least, that's how I understood it.
@mirabilos @aredridel @ubersoft no. Revealing the host name in the TLS (older TLS) threatens everyone.
@falken @aredridel @ubersoft if you’re talking about SNI: that’s mostly a newer TLS thing, and this has been precisely my criticism of SNI.
And then they go and make SNI mandatory in TLSv1.3 when IMHO it ought to have been killed with fire. It’s just a bad excuse to not do IPv6 (or work with wildcards or subjectAltName) anyway.
SAN is such a pain in the ass, and makes certs huuuuuuge. Not a good solution!
encrypted SNI is good, but we shoulda switched to SRV delegation and making the server name an allowed target of the cert. Separate this stuff into layers!
@aredridel or just not use SNI, like TLSv1 implementations pre-1.2 do.
One 443 port, one SSL certificate, period.
If you need different certificates, just put the server on a different IP address. Normal end customers have 1208925819614629174706174 IP addresses allocated to them, so that’ll suffice for a while. (Some ISPs make only 4722366482869645213694 or 18446744073709551614 addresses available, which will still… last.)
@mirabilos When IPv6 works reliably I'll do that :P
RCN still hasn't rolled it out. Total non-starter here.
@aredridel I’ve been using it for not quite 25 years, over 20 in production (for my home and hobby projects)…
… but my current employer also continues to ignore it, so I get that.
IMHO still not an excuse for SNI.
@mirabilos I mean me too but "works for me" is not 'works"
@aredridel but without SNI the pressure to support IPv6 will get larger and larger
@mirabilos Don't care. You don't break infrastructure hoping someone picks up the pieces. Tempting as it is to take a pickaxe to the roads until public transit appears.
@aredridel the right thing would have been to not even introduce SNI
@aredridel @mirabilos well... That's exactly what happened with https, though. Blacksheep intentionally broke the infrastructure to force the change.
@ubersoft @mirabilos Blacksheep didn't break shit. It showed how it already was.
@ubersoft Blacksheep? Now there’s a story and name I don’t know…
@aredridel Pickaxe is an option, but I’d rather set up protected bike lanes so we can at least bike until public transport appears ☻
@mirabilos @ubersoft Yeah. That's the thing. HTTPS with SNI is a protected bike lane. It ain't the perfect solution, but it works alright as an incremental step.
@aredridel @ubersoft nah, it’s not, it totally broke anonymity of what domain the user actually wants to visit
@roytam1 @aredridel @ubersoft @falken won’t help due to ossification (plus TLSv1.3 mandates SNI ☹)
@falken @aredridel @ubersoft excuse me, what? Where is the hostname revealed?