Hacker News new | past | comments | ask | show | jobs | submit login

Why is the linked site served over http? http://www.zynamics.com/software.html

Changing to https reveals a security cert valid for *.google.com, but not for www.zynamics.com.




Interesting. I brought up a similar issue about what browser dot org and while they took months to get it working with HTTPS, I consider it a win.

Still interesting though. I'd just use a separate certificate for this. > www.zynamics.com uses an invalid security certificate. The certificate is only valid for the following names: .google.com, .android.com, .appengine.google.com, .cloud.google.com, .google-analytics.com, .google.ca, .google.cl, .google.co.in, .google.co.jp, .google.co.uk, .google.com.ar, .google.com.au, .google.com.br, .google.com.co, .google.com.mx, .google.com.tr, .google.com.vn, .google.de, .google.es, .google.fr, .google.hu, .google.it, .google.nl, .google.pl, .google.pt, .googleadapis.com, .googleapis.cn, .googlecommerce.com, .googlevideo.com, .gstatic.cn, .gstatic.com, .gvt1.com, .gvt2.com, .metric.gstatic.com, .urchin.com, .url.google.com, .youtube-nocookie.com, .youtube.com, .youtubeeducation.com, .ytimg.com, android.clients.google.com, android.com, g.co, goo.gl, google-analytics.com, google.com, googlecommerce.com, urchin.com, youtu.be, youtube.com, youtubeeducation.com Error code: SSL_ERROR_BAD_CERT_DOMAIN


Yeah that's a sore point :-/ The downloads are served via HTTPS, though. Also, publishing the SHA1 hashes over HTTP kind of defeats the purpose, so here they are again (HackerNews is HTTPS :)):

bindiff420-debian8-amd64.deb 38fbea8070495fc8730d7c86eae03bc68fde291f bindiff420-debian8-i386.deb 49cdd6ae7ebe5b1813a5fcafaae9fde19005c824 bindiff420-win-pluginsonly.zip e2b786d405aac23aced989e02080dd69c18ab75e bindiff420-win-x86.msi 89f2eadc6582d4acca1e78db3617b5fba3eced0f bindiff-license-key.zip 95715a8bd7469106fc60b03f94f3cc87604e354c




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: