Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

That’s what I mean by non-sensitive stuff. I don’t care if someone inserts ads or changes stuff. I’ll switch ISPs if they do that. If some intermediate network does it, I’ll route around them. For stuff like this, I don’t care.

There’s a whole class of traffic I don’t care about, like this guy’s prototype or your mom’s blog or whatever.

And I like segregating stuff I care about vs stuff I don’t.

Also note that with SSL, google can still do all this, but they have the same pressure my ISP does if they ever try it.



I don't totally understand your reasoning. There is no downside to using SSL encryption and its completely free for websites to install it.

On the other hand, there are downsides to not using it (which have been previously mentioned).


There are downsides, but I don’t think any massive. I don’t know OP’s hosting situation, but there may be limitations there. Although even the most basic hosts use letsencrypt nowadays.

But I think the most obvious downside is that OP is the only one working on this and any time spent working out ssl is time away from feature development. SSL is not a key feature of OP’s product so there may be other features more important.

Simplicity is an important design principle. There are many things that have “no downside [other than cost to set up and maintain].” but have no clear value driver.

It’s quite possible that all the important stuff gets built out before users make the value of ssl really clear.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: