Re: HTTP is just fine
Kevin Chadwick <[email protected]>
| Newsgroups | gmane.comp.mozilla.security |
|---|---|
| Message-ID | <[email protected]> |
> What does security of HTTPS have to do with security of HTTP? > > Question: Is HTTPS secure? > > Answer: It depends on implementation (HTTPS enforcement, key/cert > pinning, TLS version, cipher choice, etc.) > > Question: Is HTTP secure? > > Answer: No. End of story. The world is NOT BLACK AND WHITE. A server that has no need for https is more secure without it because it is simpler and so inherently less exploitable. https is end-end but it increases the chance to control an end. arguing this isn't true because javscript may come from unchecked sources is simply idiotic as it still can anyway and needs controlling in ANY case. If your ISP/network is dodgy then change it or use a VPN service don;t substitute one problem for another as that always leads to making things worse in general. -- KISSIS - Keep It Simple So It's Securable