Re: HTTP is just fine
Hubert Kario <[email protected]>
| Newsgroups | gmane.comp.mozilla.security |
|---|---|
| Message-ID | <[email protected]> |
On Tuesday 24 November 2015 17:31:19 Kevin Chadwick wrote: > > > > > The statement "HTTP is insecure" is wrong and a lie. That's my > > > > > problem. > > > > > > > > HTTP is insecure and HTTP can't be made secure, it's a fact > > > > > > > > existence of extensions like Firesheep prove it > > > > > > Nonsense, that is likie saying the existence of a virus/rootkit > > > means > > > that Operating systems are insecure. > > > > yes, certain versions of operating systems are known to be insecure. > > Subsequently they got updates released and are no longer vulnerable. > > > > You can't update HTTP to not be insecure. You *can't* fix it. > > You completely miss the point, extensions like firesheep need access > in the first place like a trojan or local program. Your original > argument has no bearing on the discussion at all. you don't understand what firesheep does - it does not require access to computer under attack, it requires access to network on which the system under attack is and that is not exactly that hard to arrange if you're on a WiFi in a hotel/coffee house/event or on a network in school/library... it's not 1970's any more, there is no such thing as a "trusted network"* > p.s. it doesn't need fixing, however https really does from a design > point of view. Thankfully from a technical fix point of view there are > a few forks from openssl too such as libressl as well as googles. you are mixing up completely different topics while missing the elephant in the room just because one implementation has a bug doesn't make the protocol itself incorrect > Also http tunnelled over ssh is much more secure than over SSL, so it > would make most sense if you would just retract your statement > entirely. and GPG is better than S/MIME which in turn is better than plain text email both (S/MIME and HTTP+SSH) are also unusable by the average person connecting to average server HTTPS on the other hand is used by billions * - yes there are exceptions with air gapped systems, with cables not leaving a shielded room or virtual networks between virtual hosts on a single machine. But they are only that - exceptions. -- Regards, Hubert Kario Senior Quality Engineer, QE BaseOS Security team Web: www.cz.redhat.com Red Hat Czech s.r.o., Purkyňova 99/71, 612 45, Brno, Czech Republic _______________________________________________ dev-security mailing list [email protected] https://lists.mozilla.org/listinfo/dev-security
signature.asc
(application/pgp-signature, 819 B)
-----BEGIN PGP SIGNATURE----- Version: GnuPG v2 iQIcBAABCgAGBQJWVKpIAAoJEJKo0bgB0vX1neAQAJWJPBIHzLm7yw8lWNfBcCpn Dyj8sJ5Mvw9Fs0cJhTOzUha0UNjQqVCq4qFdmOn5L/sr8NfT1bM6UEEVMXFMdmZ9 ZY8R+kkyPHDuIxQ0VJSCN2YnoKrj/0sZjuPFFn1qWLN45GP6Lk4t7VETNiW1O7/e KT5T2eP4YwmjVA2ISv/OaUIAsZgTtMtfc3YWyDGH4Cug3LHfyGekk43+LGKIRRqU oUDN60XP9rMcAM6ZaWMO0IBNWcqG6MCl8ZzklUw4SzFg6MxaRQPCvLBppYAy4Tsk ELZAnLmIoMJs3gt4D/cXzMIQ9DhQHGoE2e5dhD8uDZZyFXNxxcOtlEJg214hj+K4 HUmeKd6/k68BfT9PlI4oS7C9g1r9PAg++QX95VlOWh1nb3qlb+eKh6lNmRbBCsbw 0rgDtg8Gu5wLw4Jn4E/u4jxn9ZFFclGP7Wby+l+QpgcERyQBJBPyaQNxIY6HncLv iB94lskMlYKGfPnN/npYpku3UEAddDcfgoish+j0k4agtVn5UpxPzv08phXwhD1s kNtyDT7g4MN+hH8sdSSoLBOHqAAAGUX4IcjhwfAzM78RsgHlXRRqks9EQ7QjUEAa XzaHy9CxAlg6XRiLItQVD5m8Oy7L1yLsolmynxnEPoEokM+c1hAdVaz21GUxW6mj 5aCcPDTACDCZf8BzEkAE =PKwV -----END PGP SIGNATURE-----