logoalt Hacker News

FunnyLookinHatlast Tuesday at 11:39 AM5 repliesview on HN

Anyone else surprised that the download links are plain HTTP without SSL? I know it's a page that in the past I would have typically not worried about securing - but nowadays it's SSL everything or else your browser yells at you.


Replies

maxmcdlast Tuesday at 3:45 PM

Quite surprising. It does seem like you can get an https download with

    aws s3 cp --no-sign-request s3://download.opencontent.netflix.com/sparks/creative-commons-attribution-4-intl-public-license.txt .
Which is hitting the bucket path route at: https://s3.amazonaws.com/download.opencontent.netflix.com/sp...

"aws s3 ls" similarly requests: https://s3.amazonaws.com/download.opencontent.netflix.com?li...

ronbentonlast Tuesday at 12:14 PM

Yeah, this is bad. The page almost seems like someone’s pet project that didn’t have any explicit funding and they got bored or left Netflix in 2020. I’m not sure how that would explain the lack of SSL cert except for just general lack of thoroughness.

show 3 replies
uyzstvqslast Tuesday at 12:32 PM

I'm surprised they didn't use BitTorrent, with these HTTP links as web seeds. That'd make the most sense.

show 1 reply
mrtksnlast Tuesday at 11:51 AM

The page look like zero effort given anyway, like one of the free templates you can find.

robingchanlast Tuesday at 12:25 PM

this is hosted on s3 which doesn't support HTTPS, that said - if they used cloudfront in front of this bucket, they could save $$$ and have a SSL

show 1 reply