I realise I'm going to be in the 0.1% minority on this, but yep, I do. Three reasons.
First, I've been enough places where Internet connectivity is so poor that HTTPS effectively breaks the connection. I used to stay half the week somewhere where the only connectivity was a dire, over-saturated 3G link. I couldn't browse HTTPS sites unless I was very lucky.
Second, I'm uneasy with the implication that "HTTPS=secure", in that it absolves the user of taking any responsibility for their own security. A site can require a HTTPS connection and still store the password in cleartext, for example; so unless you have a unique password, this "secure" site can still screw you. Yeah, I know HN readers understand the difference, but IMX most people dimly understand a binary distinction between "secure site" and "not secure site" and that's it.
Third and related, the corollary of "HTTPS=secure" is that "sites that only use HTTP = insecure". This is leading to a requirement that any guy who builds a website with login functionality needs to implement HTTPS, and that saddens me. The web becomes less democratic, less meritocratic, the more technical hurdles we require.
But, like I say, I realise 99.9% of people disagree with me.
First, I've been enough places where Internet connectivity is so poor that HTTPS effectively breaks the connection. I used to stay half the week somewhere where the only connectivity was a dire, over-saturated 3G link. I couldn't browse HTTPS sites unless I was very lucky.
Second, I'm uneasy with the implication that "HTTPS=secure", in that it absolves the user of taking any responsibility for their own security. A site can require a HTTPS connection and still store the password in cleartext, for example; so unless you have a unique password, this "secure" site can still screw you. Yeah, I know HN readers understand the difference, but IMX most people dimly understand a binary distinction between "secure site" and "not secure site" and that's it.
Third and related, the corollary of "HTTPS=secure" is that "sites that only use HTTP = insecure". This is leading to a requirement that any guy who builds a website with login functionality needs to implement HTTPS, and that saddens me. The web becomes less democratic, less meritocratic, the more technical hurdles we require.
But, like I say, I realise 99.9% of people disagree with me.