Introducing Secure The News, an automated tool tracking the adoption of HTTPS encryption across dozens of news websites

This meme that SSL/TLS is the biggest aspect of online security is misleading and unacceptable. It is perpetuated by OS and browser vendors with expansive, very public extravagant Certificate Authority programmes while being extremely quiet and underwhelming about other aspects of web security.

If anywhere near the amount of resources being channelled into CA programmes was channelled into other aspects of web security, Advertising would be cleaned up and accountable, not delivering malware and exploit kits. There'd be greater accountability for unnamed "Third Party Partners" that publications use for analytics. WebRTC wouldn't have been exploitable to reach past VPNs for IP addresses without permission. Software like Wordpress (which is almost impossible to correctly secure) would have been designed from the ground up with security in mind rather than as an afterthought.

Shock, horror: perhaps the number of websites getting compromised and user databases being harvested would go down with improved software quality.

Publishers more or less rely upon the insecurity of the web to do what they do with low overhead and greater convenience, ergo they won't allow much beyond SSL/TLS to be addressed.

/r/technology Thread Link - freedom.press