← Back to context

Comment by drdeca

1 day ago

http://neverssl.com/online/ seems to work for me?

Are you perhaps on an untrusted network which is spoofing that url to make it redirect somewhere else?

No, NeverSSL changed to have SSL a while back - around the time that Chrome/Firefox started throwing big warning signs and/or blocking non-https pages.

  • Wait, are you saying neverssl.com now sometimes uses SSL?

    If this is a joke, it's over my head. If not, I'm not knowledgeable enough in this space to pass judgement, but that would seem crazy to me. Like the owner should consider a domain name change :)

    • It has SSL on the main domain, and some subdomains without SSL (wildcard perhaps?). The main domain (when accessed over SSL?) redirects to a subdomain with plain HTTP.

      Kinda weird setup!

      Edit: okay, the subdomains also have SSL. I guess the random subdomain thing is to make sure it hasn’t been cached in a “this site has HTTPS” list. The HTTPS is needed, of course, to please the browser makers, as the parent says.

http://http.rip/ is one I use

  • Wow finally, a "no ssl" site that actually doesn't use SSL! I was so disappointed when "NEVERssl" added SSL, like you literally have ONE job. Some clients automatically upgrade http->https or prepend https if left unspecified, so it's nice to have an explicitly HTTP-only (IE port 80-only) service for testing/captive portals.

    This is very useful, thanks for sharing!