HTTP is just fine (was: Marking HTTP As Non-Secure)

Ben Bucksch <[email protected]>
Newsgroups gmane.comp.mozilla.security
Message-ID <[email protected]>
Chris Palmer wrote on 05.11.2015 21:05:
> We do still want to try to mark non-secure origins as such soon (early 
> next year), but 1 thing we have found is that, although the big sites 
> are HTTPS and people spend tons of time on them, there is a huge long 
> tail of non-secure sites. Over the Summer and Autumn we measured HTTPS 
> adoption, and it hasn't gone up much — so we've been spending effort 
> trying to make it easier for site operators to migrate.

No reason to throw out the baby with the bath.

Adding TLS to a site is still major work. Added with the fact that I 
can't even get IPv4 addresses for each web *host* (much less each 
domain) anymore, it gets far more complicated. "Let's encrypt" is a step 
in the right direction, but there are still plenty of problems left that 
make it difficult to set up.

Added with the fact that I consider TLS to be not strong security, given 
the hundreds of CAs being "trusted", but not being trustworthy. So, I 
don't consider it worth the effort.

Last but not least, when you're asking for everything to be encrypted, 
you're missing the point of many websites. Not all of them have a login. 
Many sites are just simple plain old web pages that give information, 
including product information and personal sites, and there's no reason 
to encrypt them.

Please note that I'm a very strong privacy advocate. But calling a 
normal HTTP "insecure" is just plain wrong. Sending passwords over HTTP 
is insecure (typically, not always). Running old browsers and email 
programs is insecure. Reading my blog unencrypted is not insecure.

Starting to flag the most common communication protocol in the world 
"insecure", while most enterprises are using age-old browser and getting 
hacked, is simply barking at the wrong tree.

Ben
_______________________________________________
dev-security mailing list
[email protected]
https://lists.mozilla.org/listinfo/dev-security
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.