Jump to content

Wikipedia:Wikipedia Signpost/2015-06-10/Technology report

From Wikipedia, the free encyclopedia

This is the current revision of this page, as edited by JPxG (talk | contribs) at 02:18, 6 January 2024 (Protected "Wikipedia:Wikipedia Signpost/2015-06-10/Technology report": old newspaper articles don't need to be continually updated, the only real edits expected here are from bots/scripts, and vandalism is extremely hard to monitor ([Edit=Require autoconfirmed or confirmed access] (indefinite) [Move=Require autoconfirmed or confirmed access] (indefinite))). The present address (URL) is a permanent link to this version.

(diff) ← Previous revision | Latest revision (diff) | Newer revision → (diff)
Technology report

Wikimedia sites are going HTTPS only

Today it was announced that Wikimedia sites are going to become HTTPS only, finishing up 10 year effort of rolling out HTTPS. In December 2005, Brion Vibber set up an experimental HTTPS server using special urls like https://secure.wikimedia.org/wikipedia/en/wiki/Main_Page. In 2011, HTTPS became available using canonical urls like https://en.wikipedia.org/wiki/Main_Page, which allowed for the usage of protocol-relative urls (//en.wikipedia.org/wiki/Main_Page) to avoid serving HTTP content in pages loaded over HTTPS (mixed content).

Since August 2013, all logged in users used HTTPS; however, that system had some drawbacks. If a user clicked an HTTP link, they would be redirected to HTTPS, but their initial click would leak what page they were trying to visit. To counter that, HTTP Strict Transport Security (HSTS) is also being rolled out, which instructs browsers to only visit the website over HTTPS. Wikimedia sites will also be added to browser's HSTS preload lists, which will make sure the browser uses HTTPS even if you have never visited the website before to see the HSTS information.

As of writing, only 7 language groups have been converted[1]: ca, el, en, he, it, ug, zh. The Russian Wikipedia has been practically HTTPS-only since August 2014[2].

Legoktm is a software engineer for the Wikimedia Foundation, and he wrote this in his volunteer capacity.