Linked by David Adams on Mon 8th Nov 2010 16:49 UTC, submitted by HAL2001
Thread beginning with comment 449150
To view parent comment, click here.
To read all comments associated with this story, please click here.
To view parent comment, click here.
To read all comments associated with this story, please click here.



Member since:
2006-01-26
Sites using phpbb, Wordpress, etc since they ususally only store name, IP, and timezone info can be exempt.
These site should be forced IMO. (at least parts of the site once you are logged in)
Shopping sites (Amazon.com), WebMail (Hotmail, Google), Banks/Financial, social sites (Facebook).
One of the reasons I've heard cited is that encrypting all communication with SSL incurs higher server load (and client for that matter - those poor cell phones have to encrypt/decrypt every request to the server).
Another thing it also limits is the ability to easily load balance cache-able resources - for example, a trick that many sites use is to farm their image or .js hosting out to other load balanced servers on different domains - which would require a connection to a different server, which creates a complicated security situation. I already see this often while using gmail https - my browser is constantly warning me that there are "some unsecured elements on the page"...
There are some companies that take this stuff seriously... Google for example even gives you a way to search on a public network without anyone else sniffing your search terms (except Google of course... but hey, they already know everything about you):
https://encrypted.google.com/