josht ([personal profile] josht) wrote in [site community profile] dw_suggestions2011-09-03 06:58 pm
Entry tags:

Support for HTTPS on all pages, including journal pages

Title:
Support for HTTPS on all pages, including journal pages

Area:
security, privacy, https,

Summary:
I'd like to have the option of using HTTPS to access all dreamwidth pages, including journal pages as well as pages on dreamwidth.org itself.

Description:
Inspired by the HTTPS Everywhere addon (https://www.eff.org/https-everywhere), I started looking through the sites I regularly visit to find which ones have HTTPS support. I frequently read journals on dreamwidth, but dreamwidth doesn't support https on journal pages; the certificate only works for www.dreamwidth.org. Also, visiting https://www.dreamwidth.org/ redirects to the login page rather than serving the front page securely; changing an http URL to https should serve the same content securely, rather than changing the content served.

Having HTTPS on all pages would secure acccounts against session-hijacking, a particular concern when on more insecure Internet connections, such as public wifi, or university or corporate networks. HTTPS would also improve privacy. The web needs more encrypted packets and less plaintext.

Poll #8378 Support for HTTPS on all pages, including journal pages
Open to: Registered Users, detailed results viewable to: All, participants: 37


This suggestion:

View Answers

Should be implemented as-is.
25 (67.6%)

Should be implemented with changes. (please comment)
0 (0.0%)

Shouldn't be implemented.
0 (0.0%)

(I have no opinion)
12 (32.4%)

(Other: please comment)
0 (0.0%)

mark: A photo of Mark kneeling on top of the Taal Volcano in the Philippines. It was a long hike. (Default)

[staff profile] mark 2011-10-27 07:35 am (UTC)(link)
We use Pound for SSL termination. I don't know the answers to these questions, honestly, this is a part of the world of tech stuff that I'm not super familiar with.