Re: Why do downloads not use HTTPS by default?

Previous Topic Next Topic
 
classic Classic list List threaded Threaded
7 messages Options
Reply | Threaded
Open this post in threaded view
|

Re: Why do downloads not use HTTPS by default?

Marcus Denker-4
It is on my TODO to change all the links… sorry for not having done that yet.

Sadly the day has just 24 hours and the end of the year time is always quite stressful.

Marcus

On 11 Dec 2017, at 00:48, Silent Walls <[hidden email]> wrote:

Today I visited https://pharo.org/gnu-linux-installation-64 to download the zip file containing the executable. To my surprise, the download is not carried out over HTTPS. The download link is http://files.pharo.org/platform/Pharo6.1-64-linux.zip. I ended up downloading the zip file using https://files.pharo.org/platform/Pharo6.1-64-linux.zip.

The point is: if HTTPS downloads are supported, why is it not the default on the download pages of the Pharo website?

Reply | Threaded
Open this post in threaded view
|

Re: Why do downloads not use HTTPS by default?

Marcus Denker-4
The link there is now fixed.

On 11 Dec 2017, at 09:14, Marcus Denker <[hidden email]> wrote:

It is on my TODO to change all the links… sorry for not having done that yet.

Sadly the day has just 24 hours and the end of the year time is always quite stressful.

Marcus

On 11 Dec 2017, at 00:48, Silent Walls <[hidden email]> wrote:

Today I visited https://pharo.org/gnu-linux-installation-64 to download the zip file containing the executable. To my surprise, the download is not carried out over HTTPS. The download link is http://files.pharo.org/platform/Pharo6.1-64-linux.zip. I ended up downloading the zip file using https://files.pharo.org/platform/Pharo6.1-64-linux.zip.

The point is: if HTTPS downloads are supported, why is it not the default on the download pages of the Pharo website?


Reply | Threaded
Open this post in threaded view
|

Re: Why do downloads not use HTTPS by default?

Stephane Ducasse-3
Thanks marcus.
Should I update all the pages of the lectures and other to use https?

Stef

On Mon, Dec 11, 2017 at 9:19 AM, Marcus Denker <[hidden email]> wrote:

> The link there is now fixed.
>
>
> On 11 Dec 2017, at 09:14, Marcus Denker <[hidden email]> wrote:
>
> It is on my TODO to change all the links… sorry for not having done that
> yet.
>
> Sadly the day has just 24 hours and the end of the year time is always quite
> stressful.
>
> Marcus
>
> On 11 Dec 2017, at 00:48, Silent Walls <[hidden email]> wrote:
>
> Today I visited https://pharo.org/gnu-linux-installation-64 to download the
> zip file containing the executable. To my surprise, the download is not
> carried out over HTTPS. The download link is
> http://files.pharo.org/platform/Pharo6.1-64-linux.zip. I ended up
> downloading the zip file using
> https://files.pharo.org/platform/Pharo6.1-64-linux.zip.
>
> The point is: if HTTPS downloads are supported, why is it not the default on
> the download pages of the Pharo website?
>
>
>

Reply | Threaded
Open this post in threaded view
|

Re: Why do downloads not use HTTPS by default?

CyrilFerlicot

On mar. 12 déc. 2017 at 00:12, Stephane Ducasse <[hidden email]> wrote:
Thanks marcus.
Should I update all the pages of the lectures and other to use https?

Stef


Wouldn't it be simpler to set an automatic redirection from the http to the https on the server? 
--
Cyril Ferlicot
https://ferlicot.fr

http://www.synectique.eu
2 rue Jacques Prévert 01,
59650 Villeneuve d'ascq France
Reply | Threaded
Open this post in threaded view
|

Re: Why do downloads not use HTTPS by default?

Marcus Denker-4


On 12 Dec 2017, at 00:18, Cyril Ferlicot <[hidden email]> wrote:


On mar. 12 déc. 2017 at 00:12, Stephane Ducasse <[hidden email]> wrote:
Thanks marcus.
Should I update all the pages of the lectures and other to use https?

For downloads that are images and the VM (everything that is executable), yes.

Stef


Wouldn't it be simpler to set an automatic redirection from the http to the https on the server? 

We could do that, too. 

I think for all downloads of *executable* code we should in addition use https:// in all links so people
see that it uses HTTPS early.

Marcus

Reply | Threaded
Open this post in threaded view
|

Re: Why do downloads not use HTTPS by default?

Stephane Ducasse-3
Ok I will try to get some time to do it.


On Tue, Dec 12, 2017 at 11:48 AM, Marcus Denker <[hidden email]> wrote:

>
>
> On 12 Dec 2017, at 00:18, Cyril Ferlicot <[hidden email]> wrote:
>
>
> On mar. 12 déc. 2017 at 00:12, Stephane Ducasse <[hidden email]>
> wrote:
>>
>> Thanks marcus.
>> Should I update all the pages of the lectures and other to use https?
>>
> For downloads that are images and the VM (everything that is executable),
> yes.
>
>> Stef
>>
>>
> Wouldn't it be simpler to set an automatic redirection from the http to the
> https on the server?
>
>
> We could do that, too.
>
> I think for all downloads of *executable* code we should in addition use
> https:// in all links so people
> see that it uses HTTPS early.
>
> Marcus
>

Reply | Threaded
Open this post in threaded view
|

Re: Why do downloads not use HTTPS by default?

Marcus Denker-4
In reply to this post by Marcus Denker-4


> On 12 Dec 2017, at 11:48, Marcus Denker <[hidden email]> wrote:
>
>
>
>> On 12 Dec 2017, at 00:18, Cyril Ferlicot <[hidden email]> wrote:
>>
>>
>> On mar. 12 déc. 2017 at 00:12, Stephane Ducasse <[hidden email]> wrote:
>> Thanks marcus.
>> Should I update all the pages of the lectures and other to use https?
>>
> For downloads that are images and the VM (everything that is executable), yes.

I have updated all links here:

https://pharo.org
https://pharo.org/web/download
https://pharo.org/gnu-linux-installation
https://pharo.org/gnu-linux-installation-64


        Marcus