Re: HTTP is just fine (was: Marking HTTP As Non-Secure)

Richard Barnes <[email protected]>
Newsgroups gmane.comp.mozilla.security
Message-ID <CAOAcki_yprxOtjdy4ROuAiQ+PtpyCzcnWCh6T30iKMqtanjXng@mail.gmail.com>
On Thu, Nov 19, 2015 at 8:40 AM, Hanno Böck <[email protected]> wrote:

> It's amazing how the same wrong arguments get repeated again and
> again...
>

+1000

All of these points have been raised and rebutted several times.  My
favorite reference is:

https://konklone.com/post/were-deprecating-http-and-its-going-to-be-okay



> On Thu, 19 Nov 2015 17:00:31 +0100
> Ben Bucksch <[email protected]> wrote:
>
> > Adding TLS to a site is still major work. Added with the fact that I
> > can't even get IPv4 addresses for each web *host* (much less each
> > domain) anymore, it gets far more complicated.
>
> You don't need an IP for every Domain. That was true 15 years ago. It
> is not any more. The solution is called SNI and it is in every major
> browser since many years.
>

To be fair, SNI is still not universal.  A single-digit percentage of
clients are still on IE/XP and Android 2.2.  However, at this point, I
think creating web sites that those clients can't access is more of a
feature than a bug.


> Added with the fact that I consider TLS to be not strong security,
> > given the hundreds of CAs being "trusted", but not being trustworthy.
> > So, I don't consider it worth the effort.
>
> Are you aware of the efforts to mitigate these problems, namely CT and
> HPKP?
>
> > Last but not least, when you're asking for everything to be
> > encrypted, you're missing the point of many websites. Not all of them
> > have a login. Many sites are just simple plain old web pages that
> > give information, including product information and personal sites,
> > and there's no reason to encrypt them.
>
> You're missing the point of HTTPS. It's not just about "encryption".
> HTTPS guarantees privacy *AND* integrity. You're arguing as if the
> second one wasn't an issue. It is.
>
> If you deliver your "information only" webpage over HTTP you have no
> guarantee that the data you send is the data the user gets. This is a
> very real issue with intermediates injecting all kinds of things into
> content (e.g. adding ads or replacing ads or injecting some kind of
> javascript doing whatever).
>

Indeed, as Kurt pointed out, if you want your information-only site to
actually provide the real information to your users, you need HTTPS.

If you don't find the injection of ads, control panels, and copyright
warnings compelling, imagine how much grief an ISP could cause you simply
by modifying a few numbers on your site.  "But your web site says it costs
$X!"




>
>
> --
> Hanno Böck
> http://hboeck.de/
>
> mail/jabber: [email protected]
> GPG: BBB51E42
>
> _______________________________________________
> dev-security mailing list
> [email protected]
> https://lists.mozilla.org/listinfo/dev-security
>
>
_______________________________________________
dev-security mailing list
[email protected]
https://lists.mozilla.org/listinfo/dev-security
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.