Re: HTTP is just fine
Stefan Arentz <[email protected]>
| Newsgroups | gmane.comp.mozilla.security |
|---|---|
| Message-ID | <CAKyLfD4Y85oO_w+KBhm-riQx-3JncOhL00ckg-s9yJbEpFTzsA@mail.gmail.com> |
On Tue, Nov 24, 2015 at 3:26 PM, Kevin Chadwick <[email protected]> wrote: > > and the greater security > > community threat assessments don't match up. And that's OK. > > "Greater security community" NO they never have as I have much higher > security standards, that of a more niche security community that is > practical paranoid!! > Kevin, this is an interesting discussion but I get the idea that you do not see the bigger picture. It makes no sense to talk about WPA2 in the context of Firesheep. Firesheep was a proof of concept. What it proved was that it is extremely simple to capture data from insecure http traffic anywhere between your browser and the web site. Yes it did so best on inseure local networks. But reality is that there can be dozens of different networks, countries, operators and types of links between you and that web site. And at every point there could be a 'Firesheep' running. We live in a world now where traffic interception happens in multiple places and for multiple reasons. This is reality now. You should assume that someone is recording and analyzing your plain internet traffic. Making that impossible is the point of end-to-end encryption. You say: yes https must be used for logins. But the rest of Amazon can run on plain http. What if I tell you that your ISP is currently intercepting plain HTTP Amazon traffic from all its subscribers so that they can build up an advertisement profile of you. They do that for all their subscribers and they sell that data to interested parties. Big data, big money. Only possible with plain HTTP. I made that up. But it may be true. Who knows. The data is insecure so simply you do not know who is capturing it and what is happening with it. Assume the worst. Maybe you don't care about your blog being secure. What kind of info is on there anyway, it is all static content. Does not have to be secure right? Well, maybe I live in china and I am reading an article about TOR proxies that you wrote. Technically there is no reason the server is secure. But the content is dangerous for me to read in China! And since it was captured by the state hosted proxy I can now expect a visit from local police, asking me why I am reading about TOR. That is the bigger picture. Look beyond local networks and bugs in OpenSSL. It is just not about that. S.