Create a gist now

Instantly share code, notes, and snippets.

Embed
A shame-list of popular websites which have not yet deployed HTTPS certificates

HTTPS vs HTTP

HTTPShame

A shame-list of popular or important websites which have not yet deployed HTTPS certificates by default.

Sites which may involve the transmission of very sensitive data, such as health or banking information, are marked with an ❗️ to signal they should deploy HTTPS-by-default as soon as possible. If you are a popular website (such as those on the Alexa Top 500 Global Sites) which finds itself on this list - and you want to be removed - you can visit Let's Encrypt about transitioning to HTTPS. It's easy, free, and will help you learn how to protect your customers/ readers!


Q: What is HTTPS?

HTTPS, or HyperText Transfer Protocol (HTTP) + Secure Sockets Layer (SSL), is a TCP/IP protocol used by web servers to securely transfer and display content over the internet. While traditionally used mostly for websites hosting online transactions and customer banking data, HTTPS is now being deployed across a wide variety of websites even if no such sensitive data is involved, mainly for authentication purposes. HTTP is less secure as it transmits data as unencrypted plaintext, which can be viewed by anyone spying on the network traffic and is also vulnerable to a variety of malicious attacks.

Q: How do I connect to sites through HTTPS?

Initiatives like HTTPS Everywhere are trying to increase the ubiquity of HTTPS deployment. It works by automatically sending a request telling websites to activate that security feature if they've made it available. However if the site does not support HTTPS at all, the plugin can't create an HTTPS connection -- you will have to use the insecure HTTP version. Some sites may support HTTPS only on certain pages, establish redirects from HTTP to their HTTPS version, or only for text and not images. Also, be aware that the content or design of a website may be different depending on whether you're accessing it over HTTP or HTTPS.

Q: How can you tell if a website is HTTPS or HTTP?

If you install the HTTPS Everywhere browser plugin, you can set it to Block all HTTP requests, which will prevent you from visiting a site or webpage which does not support HTTPS. Or you can simply look at the lock icon next to the web address, which most browsers support.

A more expansive list of HTTPS implementation (or lack thereof) for U.S. government websites, per agency, can be found at Pulse. Steve wrote a few scripts to query the Alex Top 500, including a Python script to find pure-HTTP sites.

HTTPS secure

Want to help? Tweet HTTP sites @J9Roem with the hashtag #HTTPshame or via email to einzelgaengerin@tutanota.de! Donate: 1PytMk24QZB147N9oW1jA6AhAoSsyqLhkB

@elvey

This comment has been minimized.

Show comment
Hide comment
@elvey

elvey Oct 5, 2016

Cool site. One could import or incorporate by reference: https://pulse.cio.gov/data/domains/https.csv which is a list of US Federal Government sites and whether or not they're doing HTTPS by default, at all, etc. Quite similar to HTTPShame!

elvey commented Oct 5, 2016

Cool site. One could import or incorporate by reference: https://pulse.cio.gov/data/domains/https.csv which is a list of US Federal Government sites and whether or not they're doing HTTPS by default, at all, etc. Quite similar to HTTPShame!

@Enegnei

This comment has been minimized.

Show comment
Hide comment
@Enegnei

Enegnei Oct 6, 2016

Thanks! I will add them.

Owner

Enegnei commented Oct 6, 2016

Thanks! I will add them.

@andrewnicolalde

This comment has been minimized.

Show comment
Hide comment
@andrewnicolalde

andrewnicolalde Dec 24, 2017

Amazon now uses HTTPS on every website they operate.

Amazon now uses HTTPS on every website they operate.

@robertg1

This comment has been minimized.

Show comment
Hide comment
@robertg1

robertg1 Feb 22, 2018

all the "coin" websites are now https

all the "coin" websites are now https

@robertg1

This comment has been minimized.

Show comment
Hide comment
@robertg1

robertg1 Feb 22, 2018

@bichotll

This comment has been minimized.

Show comment
Hide comment
@bichotll

bichotll Mar 9, 2018

The list should be updated as many already use https

bichotll commented Mar 9, 2018

The list should be updated as many already use https

@vuongggggg

This comment has been minimized.

Show comment
Hide comment
@vuongggggg

vuongggggg Mar 25, 2018

Aliexpress has updated HTTPS

Aliexpress has updated HTTPS

@rriemann

This comment has been minimized.

Show comment
Hide comment
@rriemann

rriemann Apr 19, 2018

Yes, many pages have https now. Cannot we have a script checking it for us? Curl could do the job I guess.

Yes, many pages have https now. Cannot we have a script checking it for us? Curl could do the job I guess.

@Moirraine1

This comment has been minimized.

Show comment
Hide comment
@Moirraine1

Moirraine1 May 17, 2018

This list needs to be updated, many that weren't, now are secure.

This list needs to be updated, many that weren't, now are secure.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment