Re: HTTP is just fine

Stefan Arentz <[email protected]>
Newsgroups gmane.comp.mozilla.security
Message-ID <CAKyLfD4Y85oO_w+KBhm-riQx-3JncOhL00ckg-s9yJbEpFTzsA@mail.gmail.com>
On Tue, Nov 24, 2015 at 3:26 PM, Kevin Chadwick <[email protected]> wrote:

> > and the greater security
> > community threat assessments don't match up. And that's OK.
>
> "Greater security community" NO they never have as I have much higher
> security standards, that of a more niche security community that is
> practical paranoid!!
>

Kevin, this is an interesting discussion but I get the idea that you do not
see the bigger picture.

It makes no sense to talk about WPA2 in the context of Firesheep. Firesheep
was a proof of concept.  What it proved was that it is extremely simple to
capture data from insecure http traffic anywhere between your browser and
the web site. Yes it did so best on inseure local networks. But reality is
that there can be dozens of different networks, countries, operators and
types of links between you and that web site. And at every point there
could be a 'Firesheep' running.

We live in a world now where traffic interception happens in multiple
places and for multiple reasons. This is reality now. You should assume
that someone is recording and analyzing your plain internet traffic.

Making that impossible is the point of end-to-end encryption.

You say: yes https must be used for logins. But the rest of Amazon can run
on plain http. What if I tell you that your ISP is currently intercepting
plain HTTP Amazon traffic from all its subscribers so that they can build
up an advertisement profile of you. They do that for all their subscribers
and they sell that data to interested parties. Big data, big money. Only
possible with plain HTTP.

I made that up. But it may be true. Who knows. The data is insecure so
simply you do not know who is capturing it and what is happening with it.
Assume the worst.

Maybe you don't care about your blog being secure. What kind of info is on
there anyway, it is all static content. Does not have to  be secure right?
Well, maybe I live in china and I am reading an article about TOR proxies
that you wrote. Technically there is no reason the server is secure. But
the content is dangerous for me to read in China! And since it was captured
by the state hosted proxy I can now expect a visit from local police,
asking me why I am reading about TOR.

That is the bigger picture. Look beyond local networks and bugs in OpenSSL.
It is just not about that.

 S.
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.