Re: HTTP is just fine

Kevin Chadwick <[email protected]>
Newsgroups gmane.comp.mozilla.security
Message-ID <[email protected]>
> What if I tell you that your ISP is currently intercepting
> plain HTTP Amazon traffic from all its subscribers so that they can build
> up an advertisement profile of you. They do that for all their subscribers
> and they sell that data to interested parties. Big data, big money. Only
> possible with plain HTTP.
> 
> I made that up. But it may be true. Who knows. The data is insecure so
> simply you do not know who is capturing it and what is happening with it.
> Assume the worst.
> 
> Maybe you don't care about your blog being secure. What kind of info is on
> there anyway, it is all static content. Does not have to  be secure right?
> Well, maybe I live in china and I am reading an article about TOR proxies
> that you wrote. Technically there is no reason the server is secure. But
> the content is dangerous for me to read in China! And since it was captured
> by the state hosted proxy I can now expect a visit from local police,
> asking me why I am reading about TOR.
> 
> That is the bigger picture. Look beyond local networks and bugs in OpenSSL.
> It is just not about that.

Thankyou for a well considered email and I know these are just a
couple of reasonable examples, however my ISP is Zen who I trust not to
do so. If you can't trust your ISP then get a VPN service becauses
https everywhere will not work and only accounts for a fraction of the
danger, after all a compromise elsewhere could lead to a compromises
of all https traffic on an end node anyway. Sites that help you to
find a VPN service that hasn't been blocked by China can enforce https
anyway, however that domain is more likely to have been blocked anyway.

I worry a little about competing companies finding out what parts
we use but the site that offers the best price actually displays "others
who bought this also bought" and probably sells it themselves.

going back to the OP's
"HTTP is just fine" email then I think he raises valid points that have
been overly criticised in a terrible manner as there is NOTHING wrong
with http and it should not be called insecure. The application of HTTP
may be insecure but http itself is not AND the application of http may
be more secure than using https. 

>>> We do still want to try to mark non-secure origins as such soon (early 
>>> next year), but 1 thing we have found is that, although the big sites 
>>> are HTTPS and people spend tons of time on them, there is a huge long 
>>> tail of non-secure sites. Over the Summer and Autumn we measured HTTPS 
>>> adoption, and it hasn't gone up much — so we've been spending effort 
>>> trying to make it easier for site operators to migrate.  

>> No reason to throw out the baby with the bath.

Perhaps non-encrypted or non-private would be a better term than
non-secure?

p.s. Trust in sites is an ongoing thing, and whilst joking a little, a
better in-security indication may be "this site uses an internet based
CMS and so can't be secure" ;)

-- 

KISSIS - Keep It Simple So It's Securable
_______________________________________________
dev-security mailing list
[email protected]
https://lists.mozilla.org/listinfo/dev-security
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.