logoalt Hacker News

What’s on HTTP?

68 pointsby elixxyesterday at 9:57 PM28 commentsview on HN

Comments

mnottoday at 11:37 AM

HTTP only is fundamentally disrespectful to your users. It places your needs above theirs. It assumes that your threat model is the same as theirs. There is no excuse for it in 2026.

show 1 reply
superkuhyesterday at 11:55 PM

HTTP is incomparibly less fragile than HTTPS which is why HTTP+HTTPS is such a great solution for websites made by human persons for human persons. Lets be clear, corporate or institutional persons using HTTPS alone is fine and reasonable. But for human use cases HTTP+HTTPS gets you the best of both worlds. No HTTPS cert system ever survives longer than a few years without human input/maintainence. There's just too much changing and too much complexity. From the software of the user to the software of the webserver.

Which is to say, HTTP is not some "ancient" tech like an analog television. It is a modern technology used today doing things that HTTPS can't.

show 5 replies
paulnpacetoday at 12:58 AM

Not very useful when most of the pages are default web server pages.

show 1 reply
swordmemyesterday at 10:14 PM

[dead]

Shangdi63046today at 4:58 AM

[dead]

HectorMallar73today at 8:38 AM

[dead]

gethwhunter34today at 9:18 AM

tldr for anyone skimming: the key insight is in section 3

unit149today at 12:38 AM

[dead]

tryauuumyesterday at 11:56 PM

[flagged]