Re: HTTP is just fine

Richard Barnes <[email protected]>
Newsgroups gmane.comp.mozilla.security
Message-ID <-5613786575545091666@unknownmsgid>
You have to detect it first.  In the Verizon/UIDH case, the ISP and
the web page were in on it, and there was no way for the user agent to
see it.

Plus, do you really want to make the average user's privacy dependent
on lawyers when there's a straightforward technical solution?  Trading
a little bit of webops time for a lot of lawyer time seems like a
great bargain.

Sent from my iPhone.  Please excuse brevity.

> On Nov 20, 2015, at 12:18, Ben Bucksch <[email protected]> wrote:
>
> That's something easy to defend against by law. This is an interference in (and alteration of) the communication between 2 parties.
>
> In Germany, that might get you in jail for 2 years (and you can't hide behind the company).
> In the US, when MSIE injected links into webpages, NYTimes sued and won.
>
> Ben
>
> Richard Barnes wrote on 20.11.2015 18:13:
>> That seems to miss the point that using HTTP also lets folks like
>> Verizon *add* cookies.  As they have in the past.
>>
>> Sent from my iPhone.  Please excuse brevity.
>>
>>> On Nov 20, 2015, at 12:09, Ben Bucksch <[email protected]> wrote:
>>>
>>> Aside from speed:
>>>
>>> HTTPS renders privoxy almost useless in terms of its privacy protection features. It can't remove cookies anymore, it can't remove images, it can't check the page. All that's left to do is a complete all-on or all-off (per host).
>>>
>>> Ben
>>> _______________________________________________
>>> dev-security mailing list
>>> [email protected]
>>> https://lists.mozilla.org/listinfo/dev-security
>
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.