Re: HTTP is just fine
Richard Barnes <[email protected]>
| Newsgroups | gmane.comp.mozilla.security |
|---|---|
| Message-ID | <-5613786575545091666@unknownmsgid> |
You have to detect it first. In the Verizon/UIDH case, the ISP and the web page were in on it, and there was no way for the user agent to see it. Plus, do you really want to make the average user's privacy dependent on lawyers when there's a straightforward technical solution? Trading a little bit of webops time for a lot of lawyer time seems like a great bargain. Sent from my iPhone. Please excuse brevity. > On Nov 20, 2015, at 12:18, Ben Bucksch <[email protected]> wrote: > > That's something easy to defend against by law. This is an interference in (and alteration of) the communication between 2 parties. > > In Germany, that might get you in jail for 2 years (and you can't hide behind the company). > In the US, when MSIE injected links into webpages, NYTimes sued and won. > > Ben > > Richard Barnes wrote on 20.11.2015 18:13: >> That seems to miss the point that using HTTP also lets folks like >> Verizon *add* cookies. As they have in the past. >> >> Sent from my iPhone. Please excuse brevity. >> >>> On Nov 20, 2015, at 12:09, Ben Bucksch <[email protected]> wrote: >>> >>> Aside from speed: >>> >>> HTTPS renders privoxy almost useless in terms of its privacy protection features. It can't remove cookies anymore, it can't remove images, it can't check the page. All that's left to do is a complete all-on or all-off (per host). >>> >>> Ben >>> _______________________________________________ >>> dev-security mailing list >>> [email protected] >>> https://lists.mozilla.org/listinfo/dev-security >