To prevent MITM attacks, Service Workers _require_ HTTPS. HTTPS isn't as accessible as unencrypted HTTP and self signed certs trigger user scarring warning messages. I do think HTTPS is better for privacy to an extent, but unless people can get signed certs for cheaper than their domain name, part of me feels like were only allowing additional web functionality for those able to afford SSL certs. Of course, cheap certs makes this argument null and void. Does anyone have any recommendations?
Also, I think it's been shown that the overhead of encryption isn't that expensive these days.
Comments
To prevent MITM attacks, Service Workers _require_ HTTPS. HTTPS isn't as accessible as unencrypted HTTP and self signed certs trigger user scarring warning messages. I do think HTTPS is better for privacy to an extent, but unless people can get signed certs for cheaper than their domain name, part of me feels like were only allowing additional web functionality for those able to afford SSL certs. Of course, cheap certs makes this argument null and void. Does anyone have any recommendations?
Also, I think it's been shown that the overhead of encryption isn't that expensive these days.
The cheapest certs I've found are from https://www.gogetssl.com/domain-validation/comodo-positive-s... but the wildcards are still pretty expensive. I can't recommend them though as I haven't bought one yet.
You can get cheap wildcard SSL from here - http://bit.ly/cheap-wildcard-ssl-cert.
Heer you can find Comodo PositiveSSL Wildcard at $58.36/Year.