Re: HTTP is just fine

Kevin Chadwick <[email protected]>
Newsgroups gmane.comp.mozilla.security
Message-ID <[email protected]>
> What does security of HTTPS have to do with security of HTTP?
> 
> Question: Is HTTPS secure?
> 
> Answer: It depends on implementation (HTTPS enforcement, key/cert 
> pinning, TLS version, cipher choice, etc.)
> 
> Question: Is HTTP secure?
> 
> Answer: No. End of story.

The world is NOT BLACK AND WHITE.

A server that has no need for https is more secure without it because it
is simpler and so inherently less exploitable. https is end-end but it
increases the chance to control an end. arguing this isn't true because
javscript may come from unchecked sources is simply idiotic as it still
can anyway and needs controlling in ANY case. If your ISP/network is
dodgy then change it or use a VPN service don;t substitute one problem
for another as that always leads to making things worse in general.

-- 

KISSIS - Keep It Simple So It's Securable
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.