• Nibodhika@lemmy.world
    link
    fedilink
    English
    arrow-up
    3
    arrow-down
    3
    ·
    1 day ago

    It is for pull requests. A user makes a change to the documentation, they want to be able to see the changes on a web page.

    So? What that has to do with SSL certificates? Do you think GitHub loses SSL when viewing PRs?

    If you don’t have them on the open web, developers and pull request authors can’t see the previews.

    You can have them in the open, but without SSL you can’t be sure what you’re accessing, i.e. it’s trivial to make a malicious site to take it’s place an MitM whoever tries to access the real one.

    The issue they had was being marked as phishing, not the SSL certificate warning page.

    Yes, a website without SSL is very likely a phishing attack, it means someone might be impersonating the real website and so it shouldn’t be trusted. Even if by a fluke of chance you hit the right site, all of your communication with it is unencrypted, so anyone in the path can see it clearly.

    • Count042@lemmy.ml
      link
      fedilink
      English
      arrow-up
      5
      arrow-down
      1
      ·
      1 day ago

      Yes, a website without SSL is very likely a phishing attack, it means someone might be impersonating the real website and so it shouldn’t be trusted. Even if by a fluke of chance you hit the right site, all of your communication with it is unencrypted, so anyone in the path can see it clearly.

      No, Google has hit me with this multiple times for sub domains where the subdomain is the name of the product and has a login page.

      So, for example, if I have emby running at emby.domain.com they’ll mark it as a phishing site. You have to add your domain to their web console and dispute the finding which is probably automated. I’ve had to do this at least three times now.

      All my certs were valid.

      • Nibodhika@lemmy.world
        link
        fedilink
        English
        arrow-up
        2
        ·
        1 day ago

        Yes, Google has miss reported my websites in the past, all of which were valid, but the person I’m replying to seemed to assume no-SSL is a requirement of the feature, and he doesn’t understand that a wrong/missing SSL is indistinguishable from a Phishing attack, and that the SSL error page is the one that warns you about phishing (with reason).