Hey everyone, I'd like everyone's input on switching forum.defcon.org over to ssl only. Brief background:
The way we do redirection from http to https is a clever kludge Cot came up with, but it prevents us from using http compression, which would speed things up for everyone. Now that mobile devices have supported http compression for years we may as well take advantage of it, not to mention it would be like getting extra free capacity.
With ssl only some of the xss and related attacks would be more difficult and MITM concerns would almost vanish.
The downside is some people might not be able to log in through proxies (I can over tor, though), at free WiFi locations, etc.
So here is a poll! Comment here and vote too!
The way we do redirection from http to https is a clever kludge Cot came up with, but it prevents us from using http compression, which would speed things up for everyone. Now that mobile devices have supported http compression for years we may as well take advantage of it, not to mention it would be like getting extra free capacity.
With ssl only some of the xss and related attacks would be more difficult and MITM concerns would almost vanish.
The downside is some people might not be able to log in through proxies (I can over tor, though), at free WiFi locations, etc.
So here is a poll! Comment here and vote too!
Comment