Re: HTTP is just fine (was: Marking HTTP As Non-Secure)
Kevin Chadwick <[email protected]>
| Newsgroups | gmane.comp.mozilla.security |
|---|---|
| Message-ID | <[email protected]> |
https://blog.mozilla.org/security/2015/04/30/deprecating-non-secure-http/ > > Last but not least, when you're asking for everything to be encrypted, > you're missing the point of many websites. Are mozilla actually asking for this? I like the letsencrypt.org accomplishments (whilst wishing they had strayed further from the traditional CA model) but the mission statement is misguided IMO. > Not all of them have a login. > Many sites are just simple plain old web pages that give information, > including product information and personal sites, and there's no reason > to encrypt them. > > Please note that I'm a very strong privacy advocate. But calling a > normal HTTP "insecure" is just plain wrong. Sending passwords over HTTP > is insecure (typically, not always). Running old browsers and email > programs is insecure. Reading my blog unencrypted is not insecure. > > Starting to flag the most common communication protocol in the world > "insecure", while most enterprises are using age-old browser and getting > hacked, is simply barking at the wrong tree. Aren't I correct in that normal HTTP will only be called insecure if it uses features such as htaccess passwords. Is there a current list of what features will be blocked? Video Card hardware acceleration being marked as insecure, might be annoying. Click to play would be the right move. It's stated that AES accelerated CPUs mean TLS doesn't matter but man y clients struggle with web content already, especially on Linux/Unix and many clients don't have intel i5 processors and actually my web server cpu is a year too old. I know the main reason for video struggling on Linux is Adobe's poor flash implementation but xombrero whilst not compatible with some sites is so much quicker at loading pages than both firefox and chrome. Perhaps the performance hit is still marginal, but I'm certainly not convinced from my own observations. Incidentally, whilst I've been hoping html5 video would improve things, the recent upgrade to itv.com has made one of my mythtv boxes in browser video frame rate drop recently, of course TLS was used before also. I have a windows box I can use in the same room that I use for silverlight but that's just annoying and isn't always available. -- KISSIS - Keep It Simple So It's Securable