when getting https links, we should use --no-check-certificate instead of silently failing when there's something wrong with the certificate...