Re: HTTP is just fine

Hubert Kario <[email protected]>
Newsgroups gmane.comp.mozilla.security
Message-ID <[email protected]>
On Tuesday 24 November 2015 17:31:19 Kevin Chadwick wrote:
> > > > > The statement "HTTP is insecure" is wrong and a lie. That's my
> > > > > problem.
> > > > 
> > > > HTTP is insecure and HTTP can't be made secure, it's a fact
> > > > 
> > > > existence of extensions like Firesheep prove it
> > > 
> > > Nonsense, that is likie saying the existence of a virus/rootkit
> > > means
> > > that Operating systems are insecure.
> > 
> > yes, certain versions of operating systems are known to be insecure.
> > Subsequently they got updates released and are no longer vulnerable.
> > 
> > You can't update HTTP to not be insecure. You *can't* fix it.
> 
> You completely miss the point, extensions like firesheep need access
> in the first place like a trojan or local program. Your original
> argument has no bearing on the discussion at all.

you don't understand what firesheep does - it does not require access to 
computer under attack, it requires access to network on which the system 
under attack is

and that is not exactly that hard to arrange if you're on a WiFi in a 
hotel/coffee house/event or on a network in school/library...

it's not 1970's any more, there is no such thing as a "trusted network"*

> p.s. it doesn't need fixing, however https really does from a design
> point of view. Thankfully from a technical fix point of view there are
> a few forks from openssl too such as libressl as well as googles.

you are mixing up completely different topics while missing the elephant 
in the room

just because one implementation has a bug doesn't make the protocol 
itself incorrect

> Also http tunnelled over ssh is much more secure than over SSL, so it
> would make most sense if you would just retract your statement
> entirely.

and GPG is better than S/MIME which in turn is better than plain text 
email

both (S/MIME and HTTP+SSH) are also unusable by the average person 
connecting to average server

HTTPS on the other hand is used by billions


 * - yes there are exceptions with air gapped systems, with cables not 
leaving a shielded room or virtual networks between virtual hosts on a 
single machine. But they are only that - exceptions.
-- 
Regards,
Hubert Kario
Senior Quality Engineer, QE BaseOS Security team
Web: www.cz.redhat.com
Red Hat Czech s.r.o., Purkyňova 99/71, 612 45, Brno, Czech Republic

_______________________________________________
dev-security mailing list
[email protected]
https://lists.mozilla.org/listinfo/dev-security
signature.asc (application/pgp-signature, 819 B)
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2

iQIcBAABCgAGBQJWVKpIAAoJEJKo0bgB0vX1neAQAJWJPBIHzLm7yw8lWNfBcCpn
Dyj8sJ5Mvw9Fs0cJhTOzUha0UNjQqVCq4qFdmOn5L/sr8NfT1bM6UEEVMXFMdmZ9
ZY8R+kkyPHDuIxQ0VJSCN2YnoKrj/0sZjuPFFn1qWLN45GP6Lk4t7VETNiW1O7/e
KT5T2eP4YwmjVA2ISv/OaUIAsZgTtMtfc3YWyDGH4Cug3LHfyGekk43+LGKIRRqU
oUDN60XP9rMcAM6ZaWMO0IBNWcqG6MCl8ZzklUw4SzFg6MxaRQPCvLBppYAy4Tsk
ELZAnLmIoMJs3gt4D/cXzMIQ9DhQHGoE2e5dhD8uDZZyFXNxxcOtlEJg214hj+K4
HUmeKd6/k68BfT9PlI4oS7C9g1r9PAg++QX95VlOWh1nb3qlb+eKh6lNmRbBCsbw
0rgDtg8Gu5wLw4Jn4E/u4jxn9ZFFclGP7Wby+l+QpgcERyQBJBPyaQNxIY6HncLv
iB94lskMlYKGfPnN/npYpku3UEAddDcfgoish+j0k4agtVn5UpxPzv08phXwhD1s
kNtyDT7g4MN+hH8sdSSoLBOHqAAAGUX4IcjhwfAzM78RsgHlXRRqks9EQ7QjUEAa
XzaHy9CxAlg6XRiLItQVD5m8Oy7L1yLsolmynxnEPoEokM+c1hAdVaz21GUxW6mj
5aCcPDTACDCZf8BzEkAE
=PKwV
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.