Jump to content

Primary: Sky Slate Blackcurrant Watermelon Strawberry Orange Banana Apple Emerald Chocolate Marble
Secondary: Sky Slate Blackcurrant Watermelon Strawberry Orange Banana Apple Emerald Chocolate Marble
Pattern: Blank Waves Squares Notes Sharp Wood Rockface Leather Honey Vertical Triangles
Photo

Why are pages served through https, but the actual images aren't?

- - - - -

  • Please log in to reply
5 replies to this topic

#1
udarnel

udarnel

    Potato Spud

  • Members
  • 24 posts

As title says. IMHO there's no point, while it does damage because it prevents users to set "block mixed content in https pages" in the browser, which is an important security option for websites where encryption matters (shopping, banking, etc). I'm not saying you must go all https if there are technical issues or costs in doing so, but you could just go http then, as it's of little use if such a core part of the page is leaked out anyway


Edited by udarnel, 05 January 2018 - 10:26 AM.


#2
Natureboy

Natureboy

    Baked Potato

  • Donator
  • 1,162 posts
  • Locationdeep in the forest

https is useful for protecting password security, so having the forum pages https helps with that.  On the other hand, the ad revenue that (mostly) pays for batoto servers comes from ad networks that don't use https (yet). Hence we're stuck with mixed content for a while.



#3
Daktyl

Daktyl

    Discord King

  • Contrib Mods
  • 825 posts
  • LocationMI, USA

Honestly, I'm not sure why img.bato.to isn't https. My guess is that when Grumpy first got tls certs, he had to pay for them and decided to just encrypt the main forum and not the subdomains. Back then, letsencrypt and mixed-content warnings didn't exist

 

As for why he hasn't updated to newer certs with subdomains included... probably just not worth the time and effort since it works fine.


My words are my own, and do not represent Batoto in any way, shape, or form unless otherwise stated in the post itself ^.^


#4
udarnel

udarnel

    Potato Spud

  • Members
  • 24 posts

Probably as Dactyl said, then. If the cost of tls encryption depends on bandwith usage, it makes sense that img.bato would be by far the most expensive.



#5
Daktyl

Daktyl

    Discord King

  • Contrib Mods
  • 825 posts
  • LocationMI, USA

Probably as Dactyl said, then. If the cost of tls encryption depends on bandwith usage, it makes sense that img.bato would be by far the most expensive.


It's not that the cost was dependent upon bandwidth, it's that the type of certs that enabled you to cover all subdomains used to be relatively expensive.

HTTPS on the image servers would be interesting, as it might enable the images to be downloaded (very slightly) faster via HTTP/2, but would also force the image server to encrypt every image sent out... which would dramatically increase the CPU usage on those servers.

Edited by Daktyl, 07 January 2018 - 07:46 PM.
double post due to internet fk up

My words are my own, and do not represent Batoto in any way, shape, or form unless otherwise stated in the post itself ^.^


#6
udarnel

udarnel

    Potato Spud

  • Members
  • 24 posts

thank'you for clarifying, now I understand more.