Question re: http to https
Discussion
I have a large http site - it's been up 25 years, so lots of pages/images with http addresses.
How much would I expect to pay someone with a brain and experience to make my domain https? And who should I be talking to?
(If I tried it, I would fail and the entire World Wide Web would probably crash)
TIA
How much would I expect to pay someone with a brain and experience to make my domain https? And who should I be talking to?
(If I tried it, I would fail and the entire World Wide Web would probably crash)
TIA
Do you know what platform your site is hosted on? Sometimes it can be relatively "easy" if there's a control panel like cPanel but could be worth speaking to your hosting provider if all this alien to you.
Don't let somebody try to charge for you the SSL certificate which underpins HTTPS - Let's Encrypt and Zero SSL both issue them for free. They need renewing every 90 days but that can be done automatically if setup correctly.
Don't let somebody try to charge for you the SSL certificate which underpins HTTPS - Let's Encrypt and Zero SSL both issue them for free. They need renewing every 90 days but that can be done automatically if setup correctly.
You could set Apache / nginx to auto redirect any incoming links for http://getcarter.com/myimage.png to https://getcarter.com/myimage.png via HTTP 302. Should be totally transparent and need no link updating.
Although you coooould do a Find and Replace, but some stuff might not have valid HTTPS if you link to outside places (unlikely)
ETA assume you have some form of VPS setup with a web server (apache or nginx usually?)
Although you coooould do a Find and Replace, but some stuff might not have valid HTTPS if you link to outside places (unlikely)
ETA assume you have some form of VPS setup with a web server (apache or nginx usually?)
MikeHo said:
Interesting, over zealous security. It’s not like you’re submitting any data or such.
But the site is leaving itself vulnerable to MITM content injection when unsecured. And that content could be anything, from annoying adverts added by your coffee shop's free WiFi service, to malicious JavaScript orchestrated by Governments annoyed that their citizens might bypass restrictions on what they deem acceptable viewing.That's how China managed to DDOS Github using their Great Cannon attack tool - it weaponised visitors of unencrypted sites, inserting malicious JavaScript. Those visitors unknowingly became attack vectors.
No excuse not to be using https these days.
Gassing Station | Computers, Gadgets & Stuff | Top of Page | What's New | My Stuff



Drop me a PM. 
