Re: HTTP is just fine

Joerg Stephan <[email protected]>
Newsgroups gmane.comp.mozilla.security
Message-ID <[email protected]>
Good morning,

sorry for being late to the discussion, so just my 2 cents.

I think HTTP is still okay. It is still in use for a reason.
I also think that we maybe should target more towards the awareness of 
people and maybe add the option to set paranoid mode in Firefox for 
people who do not want to use HTTP at all. This would make sense. There 
are so many nice tools in the world from NoScript to HTTPS tools, which 
it is maybe time to bring them into Firefox itself.

Honestly, I would love to have a button in the status row where I can 
simply disable all based HTTP traffic. I would tell my parents to press 
it as soon as they want to do banking stuff.

Am 19.11.2015 um 17:40 schrieb Hanno Böck:
> It's amazing how the same wrong arguments get repeated again and
> again...
>
> On Thu, 19 Nov 2015 17:00:31 +0100
> Ben Bucksch <[email protected]> wrote:
>
>> Adding TLS to a site is still major work. Added with the fact that I
>> can't even get IPv4 addresses for each web *host* (much less each
>> domain) anymore, it gets far more complicated.
> You don't need an IP for every Domain. That was true 15 years ago. It
> is not any more. The solution is called SNI and it is in every major
> browser since many years.
>
>
>> Added with the fact that I consider TLS to be not strong security,
>> given the hundreds of CAs being "trusted", but not being trustworthy.
>> So, I don't consider it worth the effort.
> Are you aware of the efforts to mitigate these problems, namely CT and
> HPKP?
>
>> Last but not least, when you're asking for everything to be
>> encrypted, you're missing the point of many websites. Not all of them
>> have a login. Many sites are just simple plain old web pages that
>> give information, including product information and personal sites,
>> and there's no reason to encrypt them.
> You're missing the point of HTTPS. It's not just about "encryption".
> HTTPS guarantees privacy *AND* integrity. You're arguing as if the
> second one wasn't an issue. It is.
>
> If you deliver your "information only" webpage over HTTP you have no
> guarantee that the data you send is the data the user gets. This is a
> very real issue with intermediates injecting all kinds of things into
> content (e.g. adding ads or replacing ads or injecting some kind of
> javascript doing whatever).
>
>
>
>
> _______________________________________________
> dev-security mailing list
> [email protected]
> https://lists.mozilla.org/listinfo/dev-security

-- 
--
Kind regards

Joerg Stephan, SSCP
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.