Re: HTTP is just fine
Kevin Chadwick <[email protected]>
| Newsgroups | gmane.comp.mozilla.security |
|---|---|
| Message-ID | <[email protected]> |
> What if I tell you that your ISP is currently intercepting > plain HTTP Amazon traffic from all its subscribers so that they can build > up an advertisement profile of you. They do that for all their subscribers > and they sell that data to interested parties. Big data, big money. Only > possible with plain HTTP. > > I made that up. But it may be true. Who knows. The data is insecure so > simply you do not know who is capturing it and what is happening with it. > Assume the worst. > > Maybe you don't care about your blog being secure. What kind of info is on > there anyway, it is all static content. Does not have to be secure right? > Well, maybe I live in china and I am reading an article about TOR proxies > that you wrote. Technically there is no reason the server is secure. But > the content is dangerous for me to read in China! And since it was captured > by the state hosted proxy I can now expect a visit from local police, > asking me why I am reading about TOR. > > That is the bigger picture. Look beyond local networks and bugs in OpenSSL. > It is just not about that. Thankyou for a well considered email and I know these are just a couple of reasonable examples, however my ISP is Zen who I trust not to do so. If you can't trust your ISP then get a VPN service becauses https everywhere will not work and only accounts for a fraction of the danger, after all a compromise elsewhere could lead to a compromises of all https traffic on an end node anyway. Sites that help you to find a VPN service that hasn't been blocked by China can enforce https anyway, however that domain is more likely to have been blocked anyway. I worry a little about competing companies finding out what parts we use but the site that offers the best price actually displays "others who bought this also bought" and probably sells it themselves. going back to the OP's "HTTP is just fine" email then I think he raises valid points that have been overly criticised in a terrible manner as there is NOTHING wrong with http and it should not be called insecure. The application of HTTP may be insecure but http itself is not AND the application of http may be more secure than using https. >>> We do still want to try to mark non-secure origins as such soon (early >>> next year), but 1 thing we have found is that, although the big sites >>> are HTTPS and people spend tons of time on them, there is a huge long >>> tail of non-secure sites. Over the Summer and Autumn we measured HTTPS >>> adoption, and it hasn't gone up much — so we've been spending effort >>> trying to make it easier for site operators to migrate. >> No reason to throw out the baby with the bath. Perhaps non-encrypted or non-private would be a better term than non-secure? p.s. Trust in sites is an ongoing thing, and whilst joking a little, a better in-security indication may be "this site uses an internet based CMS and so can't be secure" ;) -- KISSIS - Keep It Simple So It's Securable _______________________________________________ dev-security mailing list [email protected] https://lists.mozilla.org/listinfo/dev-security