boingboing.net is in the process of implementing HTTPS. As part of this change, we've changed CDNs on our end.
It looks to me that at some point in the past, someone decided they could jury-rig boingboing to be active by piggybacking on our old CDNs existing HTTPS certificate. they did this by rewriting requests to our CDN to instead use their domain.
Imagine their (and our!) surprise when suddenly after changing providers, users of HTTPS everywhere suddenly had a broken BB experience! I'm not sure where that ruleset came from, or the idea for this hack, but unfortunately everyone using the current ruleset is now broken.
For now, boingboing (mostly) works via HTTPS. Over the next week or so we'll correct the rest of the mixed-content errors (most of which are the result of third parties), however the media.boingboing.net domain is ready to go with HTTPS.
so, my recommendation is to re-enable the ruleset, but without the domain remapping for media. It should simply rewrite any http: media requests to https (which is fine, and should work without issue if they visit the http version of boingboing.net).
In the next few weeks, I'll open a new issue to enable the site fully, once the rest of the site has cleaned out mixed content errors and is ready to go. :)
Thanks!
Ken Snider
Sysadmin, Boing Boing
boingboing.net is in the process of implementing HTTPS. As part of this change, we've changed CDNs on our end.
It looks to me that at some point in the past, someone decided they could jury-rig boingboing to be active by piggybacking on our old CDNs existing HTTPS certificate. they did this by rewriting requests to our CDN to instead use their domain.
Imagine their (and our!) surprise when suddenly after changing providers, users of HTTPS everywhere suddenly had a broken BB experience! I'm not sure where that ruleset came from, or the idea for this hack, but unfortunately everyone using the current ruleset is now broken.
For now, boingboing (mostly) works via HTTPS. Over the next week or so we'll correct the rest of the mixed-content errors (most of which are the result of third parties), however the media.boingboing.net domain is ready to go with HTTPS.
so, my recommendation is to re-enable the ruleset, but without the domain remapping for media. It should simply rewrite any http: media requests to https (which is fine, and should work without issue if they visit the http version of boingboing.net).
In the next few weeks, I'll open a new issue to enable the site fully, once the rest of the site has cleaned out mixed content errors and is ready to go. :)
Thanks!
Ken Snider
Sysadmin, Boing Boing