I've had a few conversations with other advocacy nonprofits who are not using https, even when they know they are being targeted for surveillance. It seems the biggest reason they don't switch is because their IT staff would bitch about the work and they don't want to sour the relationship between management and IT. Typical underfunded IT bureaucracy and politics.
What I've started to do is offer to play bad cop, and come in as a consultant and take the heat from IT when I propose the work to switch to https. That way, IT bitches about the consultant and not management.
What I've started to do is offer to play bad cop, and come in as a consultant and take the heat from IT when I propose the work to switch to https. That way, IT bitches about the consultant and not management.