Re: HTTP is just fine
Joerg Stephan <[email protected]>
| Newsgroups | gmane.comp.mozilla.security |
|---|---|
| Message-ID | <[email protected]> |
Good morning, sorry for being late to the discussion, so just my 2 cents. I think HTTP is still okay. It is still in use for a reason. I also think that we maybe should target more towards the awareness of people and maybe add the option to set paranoid mode in Firefox for people who do not want to use HTTP at all. This would make sense. There are so many nice tools in the world from NoScript to HTTPS tools, which it is maybe time to bring them into Firefox itself. Honestly, I would love to have a button in the status row where I can simply disable all based HTTP traffic. I would tell my parents to press it as soon as they want to do banking stuff. Am 19.11.2015 um 17:40 schrieb Hanno Böck: > It's amazing how the same wrong arguments get repeated again and > again... > > On Thu, 19 Nov 2015 17:00:31 +0100 > Ben Bucksch <[email protected]> wrote: > >> Adding TLS to a site is still major work. Added with the fact that I >> can't even get IPv4 addresses for each web *host* (much less each >> domain) anymore, it gets far more complicated. > You don't need an IP for every Domain. That was true 15 years ago. It > is not any more. The solution is called SNI and it is in every major > browser since many years. > > >> Added with the fact that I consider TLS to be not strong security, >> given the hundreds of CAs being "trusted", but not being trustworthy. >> So, I don't consider it worth the effort. > Are you aware of the efforts to mitigate these problems, namely CT and > HPKP? > >> Last but not least, when you're asking for everything to be >> encrypted, you're missing the point of many websites. Not all of them >> have a login. Many sites are just simple plain old web pages that >> give information, including product information and personal sites, >> and there's no reason to encrypt them. > You're missing the point of HTTPS. It's not just about "encryption". > HTTPS guarantees privacy *AND* integrity. You're arguing as if the > second one wasn't an issue. It is. > > If you deliver your "information only" webpage over HTTP you have no > guarantee that the data you send is the data the user gets. This is a > very real issue with intermediates injecting all kinds of things into > content (e.g. adding ads or replacing ads or injecting some kind of > javascript doing whatever). > > > > > _______________________________________________ > dev-security mailing list > [email protected] > https://lists.mozilla.org/listinfo/dev-security -- -- Kind regards Joerg Stephan, SSCP