Re: HTTP is just fine

Kevin Chadwick <[email protected]>
Newsgroups gmane.comp.mozilla.security
Message-ID <[email protected]>
> > > > The statement "HTTP is insecure" is wrong and a lie. That's my
> > > > problem.  
> > > 
> > > HTTP is insecure and HTTP can't be made secure, it's a fact
> > > 
> > > existence of extensions like Firesheep prove it  
> > 
> > Nonsense, that is likie saying the existence of a virus/rootkit means
> > that Operating systems are insecure.  
> 
> yes, certain versions of operating systems are known to be insecure. 
> Subsequently they got updates released and are no longer vulnerable.
> 
> You can't update HTTP to not be insecure. You *can't* fix it.

You completely miss the point, extensions like firesheep need access in
the first place like a trojan or local program. Your original argument
has no bearing on the discussion at all.

p.s. it doesn't need fixing, however https really does from a design
point of view. Thankfully from a technical fix point of view there are a
few forks from openssl too such as libressl as well as googles.

Also http tunnelled over ssh is much more secure than over SSL, so it
would make most sense if you would just retract your statement
entirely.

-- 

KISSIS - Keep It Simple So It's Securable
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.