Re: HTTP is just fine
Kevin Chadwick <[email protected]>
| Newsgroups | gmane.comp.mozilla.security |
|---|---|
| Message-ID | <[email protected]> |
> > > > The statement "HTTP is insecure" is wrong and a lie. That's my > > > > problem. > > > > > > HTTP is insecure and HTTP can't be made secure, it's a fact > > > > > > existence of extensions like Firesheep prove it > > > > Nonsense, that is likie saying the existence of a virus/rootkit means > > that Operating systems are insecure. > > yes, certain versions of operating systems are known to be insecure. > Subsequently they got updates released and are no longer vulnerable. > > You can't update HTTP to not be insecure. You *can't* fix it. You completely miss the point, extensions like firesheep need access in the first place like a trojan or local program. Your original argument has no bearing on the discussion at all. p.s. it doesn't need fixing, however https really does from a design point of view. Thankfully from a technical fix point of view there are a few forks from openssl too such as libressl as well as googles. Also http tunnelled over ssh is much more secure than over SSL, so it would make most sense if you would just retract your statement entirely. -- KISSIS - Keep It Simple So It's Securable