Artifacts Gallery Guilds Search Wiki Login Register

Welcome, Guest. Please login or register. - Thinking of joining?
September 09, 2026 - @833.21
Activity rating: Four Stars Posts & Arts: 72/1k.beats Random | Recent Posts | Guild Recents
News: inconvenience is counterculture :eyes: Guild Events: weekly zine theme 11: tools

+  MelonLand Forum
|-+  Life & The Web
| |-+  ✁ ∙ Web Crafting
| | |-+  What is HTTP? What is HTTPS? Should I use it?


« previous next »
Pages: 1 [2] Print Embed
Author Topic: What is HTTP? What is HTTPS? Should I use it?  (Read 3386 times)
Rubbereon
Sr. Member ⚓︎
****
View Profile WWWArt


⛺︎ My Room
SpaceHey: Friend Me!
Matrix: Chat!
XMPP: Chat!

Guild Memberships:
Artifacts:
NoSmoking!Hope, the silliest ink kittayyVisited on Melon's 10th Anniversary!Joined 2025!
« Reply #15 on: August 08, 2026 @786.12 » Embed

Don't forget to mention HTTPS Everywhere. Despite having been huge at some point in time, it slowly faded out of people's consciousness over years. On top of that any gen alpha or beta will have never seen or heard of it before.

I think it's important given that it took way too long for browsers to add a way to automatically resolve to HTTPS. I vaguely remember using it all the way back to around 2010 or whenever's the earliest I heard of it, but that's about it. Because it got delisted from everywhere, if you move computers and rely on Firefox or Chrome sync (the former for me) the addon is pretty much gone for good for ya. Thing I hate too because other addons I don't really remember the names of, (one of them was modheader I think?) got delisted and that meant finding an alternative for both of them.

Logged

https://bettysgraphics.neocities.org/images/animals/cat%20695.gifFuzzy fwiendhttps://bettysgraphics.neocities.org/images/animals/cat%20696.gifhttps://bettysgraphics.neocities.org/images/animals/cat%20697.gif
https://rubbereon.nekoweb.org/img/penguin.gifLinux userhttps://rubbereon.nekoweb.org/img/penguin.gif
↓ All my web profiles are available on this website ↓
https://fursona.directory/@rubbereon :eyes:

Artifact Swap: pearl yappin kittaydiamond yappin kittayGreen Spiffo
meowcat
Newbie
*
View Profile WWW


⛺︎ My Room

Artifacts:
Joined 2026!
« Reply #16 on: August 26, 2026 @778.37 » Embed

With the thing about SSL certificates having a cost, you can use Cloudflare to get free SSL to cover your whole domain. Though it does mean adjusting your nameservers to point to Cloudflare.

Logged
Dan Q
Hero Member ⚓︎
*****
View Profile WWWArt


I have no idea what I am doing
⛺︎ My Room
RSS: RSS

Guild Memberships:
Artifacts:
Dan Q Cruisin'I DIDN'T meet Dan Q on Melonland!Visited on Melon's 10th Anniversary!
« Reply #17 on: August 27, 2026 @511.76 » Embed

With the thing about SSL certificates having a cost, you can use Cloudflare to get free SSL to cover your whole domain...

The gold standard of free SSL certificates IMHO remains Lets Encrypt, which doesn't require you to route your traffic through Cloudflare. (If you want Cloudflare anyway, you might as well use theirs, of course!)

Also: note that you don't have to change your nameservers to use Cloudflare. A/AAAA/CNAME/ALIAS records are sufficient (and CAA, if you use it) if you're happy with your nameservers where they are; the process is different, but just wanted to flag that the option is there!

Logged

https://danq.me/_q26t/badges/dan-q-88x31-lighter.gif https://danq.me/_q26t/badges/dan-q-88x31-peekaboo-scroller.gif https://beige-buttons.danq.dev/beige-buttons-88x31.gif https://embed-html.danq.dev/embed-html-88x31.gif

Artifact Swap: PolyamorousI met Dan Q on Melonland!Joined 2025!
meowcat
Newbie
*
View Profile WWW


⛺︎ My Room

Artifacts:
Joined 2026!
« Reply #18 on: August 27, 2026 @682.71 » Embed

If I recall correctly, Certbot can vend a certificate for free as well.

Logged
Dan Q
Hero Member ⚓︎
*****
View Profile WWWArt


I have no idea what I am doing
⛺︎ My Room
RSS: RSS

Guild Memberships:
Artifacts:
Dan Q Cruisin'I DIDN'T meet Dan Q on Melonland!Visited on Melon's 10th Anniversary!
« Reply #19 on: August 27, 2026 @732.82 » Embed

If I recall correctly, Certbot can vend a certificate for free as well.

Certbot is a program that uses a protocol called ACME to prove that you own a domain name. It doesn't sign certificates itself. It does this proof so that a Certificate Authority (that supports the protocol) can give you a free certificate. By default, it uses Let's Encrypt, who contributed in a large part to its creation.

Certbot can also use any other ACME-capable Certificate Authority, if you tell it to: e.g. you can use it with Google Trust Services or ZeroSSL. But almost all of these CAs just release their own ACME clients instead in which their CA is the default!

So yeah - probably what you're thinking of when you mention Certbot is actually just Let's Encrypt again! They get everywhere!

Logged

https://danq.me/_q26t/badges/dan-q-88x31-lighter.gif https://danq.me/_q26t/badges/dan-q-88x31-peekaboo-scroller.gif https://beige-buttons.danq.dev/beige-buttons-88x31.gif https://embed-html.danq.dev/embed-html-88x31.gif

Artifact Swap: PolyamorousI met Dan Q on Melonland!Joined 2025!
Adam
Casual Poster ⚓︎
*
View Profile WWWArt

n3rd
⛺︎ My Room
SpaceHey: Friend Me!

Guild Memberships:
Artifacts:
Joined 2025!
« Reply #20 on: August 29, 2026 @552.99 » Embed

Quote from: Dan Q
Well done, I guess?
I did it!   :wink:


With the thing about SSL certificates having a cost, you can use Cloudflare to get free SSL to cover your whole domain. Though it does mean adjusting your nameservers to point to Cloudflare.
Any time I see CF mentioned, I feel obligated to share my thoughts.
Any time that you use Cloudflare, they set a very strong expectation that you will use their proxy service

For example, here's Cloudlfare's SSL/TLS page. When we click the "View Docs" button, we're greeted with this:

Quote
SSL/TLS certificates encrypt traffic between visitors and your website, preventing eavesdropping and data tampering. Because Cloudflare sits between your visitors and your origin server, two certificates can be involved in a single request[...]
Wait, what? There's nothing about TLS that requires a random mega-corp to intercept all of your traffic. They're immediately operating on the expectation that you will give them that access.  And if you went to CF simply trying to understand how to add TLS to your site, you are going to end up using their proxy service because they typically avoid telling you that there's any alternative.

Now, their proxy service can offer some awesome benefits if you're hosting your own website, like bypassing NAT and local firewall rules, but their position as a man-in-the-middle also has certain privacy and security implications, which tend to get glossed over.

In order to provide their services, they need to terminate TLS (decrypt) the data passing through them. While it's incredibly unlikely that they would ever abuse this ability, it does, in theory, allow them to alter and censor your page's content without the knowledge of you or your users. I created a demonstration of this on my blog, here.

Now, it's totally fair to trust Cloudflare. They're a massive company, and they have huge profits that could be seriously jeopardized if they began to misuse or abuse their customers* trust; in other words, there's no benefit to them to risk their reputation just to screw with your personal site... But, if you're someone who enjoys the smaller-web because you value privacy, security, and freedom of expression, then it's worth at least considering whether you want to intentionally give them that trust.


* It's potentially questionable whether you're actually their customer in this situation. As the saying goes, if you're not paying for a service, then you're not the customer --you're the product.

Logged

-Adam
Dan Q
Hero Member ⚓︎
*****
View Profile WWWArt


I have no idea what I am doing
⛺︎ My Room
RSS: RSS

Guild Memberships:
Artifacts:
Dan Q Cruisin'I DIDN'T meet Dan Q on Melonland!Visited on Melon's 10th Anniversary!
« Reply #21 on: August 29, 2026 @727.04 » Embed

Any time I see CF mentioned, I feel obligated to share my thoughts.

All well-said.

Personally, I wouldn't use CloudFlare for, well, almost-anything! If you need CDN support, edge caching, or a Web firewall, there are alternatives that are just as good that don't put you on the same single-point-of-failure as everybody else.

But note that you don't have to use them for SSL termination/re-encryption, if you use them as a proxy. They have a zero-trust model that doesn't involve re-encryption. Of course, you're still trusting them not to "rug pull" that unless you use HPKP (or an unusual CAA, maybe?) but yeah; the option is there if you really want.

But mostly, I'm with you, and yeah: CloudFlare's not to my taste, personally.

Logged

https://danq.me/_q26t/badges/dan-q-88x31-lighter.gif https://danq.me/_q26t/badges/dan-q-88x31-peekaboo-scroller.gif https://beige-buttons.danq.dev/beige-buttons-88x31.gif https://embed-html.danq.dev/embed-html-88x31.gif

Artifact Swap: PolyamorousI met Dan Q on Melonland!Joined 2025!
Pages: 1 [2] Print Embed 
« previous next »
 

Melonking.Net © Always and ever was! SMF 2.0.19 | SMF © 2021 | Privacy Notice | Send Feedback | Supporters ♥ Forum Guide | Rules | RSS | WAP | Mobile


MelonLand Badges and Other Melon Sites!

MelonLand Project! Visit the MelonLand Forum! Support the Forum
Visit Melonking.Net! Visit the Gif Gallery! Pixel Sea TamaNOTchi
@000 Melon
Land
Editor Recent Edits Tenement Arcade Random Link Land → Forum Art Hub Chat Webring Want to Login or Join ? Web Craft Guide Graphic Catalogue Wiki Newsletters Image Stream Zap!
Minecraft: Online
Join: craft.melonking.net