cross-posted from: https://lemmy.ml/post/14100831

"No, seriously. All those things Google couldn’t find anymore? Top of the search pile. Queries that generated pages of spam in Google results? Fucking pristine on Kagi – the right answers, over and ov

  • @[email protected]
    link
    fedilink
    English
    362 months ago

    They’ve stubbornly not gotten an SSL because they transact 0 data beyond band name searches.

    Even if sites do not store user account data, such as passwords, ALL websites, and I mean ALL, handle user data, because merely accessing pages (urls) is user data.

    Stubbornness is not a good reason not to setup SSL. Encryption should always be on, all the time, for everything.

    • @[email protected]
      link
      fedilink
      English
      14
      edit-2
      2 months ago

      And it’s not only about user data, it would also expose the website to content spoofing in public wifi, which would for example allow the attacker to inject fishing content in the website.

      SSL encrypts the data you’re sending but it also ensures that you’re communicating only with who you think you are. Without SSL you can’t be confident about any of that.

      • @pixxelkick
        link
        English
        12 months ago

        If a website has literally no login system, there’s nothing to phish.

        There is honestly no reason to use SSL on a static website that has no login system and just displays some content.

        IE a static blog or etc, where the only content on the website is just “look at this stuff, okay thank you!”

        • @[email protected]
          link
          fedilink
          English
          12 months ago

          That’s still my point, for example you could inject your own login system “create an account to keep track of your favorite artists, or some new shiny feature”. For there you can get people’s personal information, potentially a password they use on other services.

          An URL is something the general public will trust, if the content can be messed with you repurpose the website’s reputation. I took phishing as an example but even my not-so-creative and non-expert brain can think of other things : asking for donations, propaganda, advertising, censorship, …

    • db0
      link
      fedilink
      English
      -42 months ago

      Ssl doest hide the url you’re visiting