Re: HTTP is just fine (was: Marking HTTP As Non-Secure)

Kevin Chadwick <[email protected]>
Newsgroups gmane.comp.mozilla.security
Message-ID <[email protected]>
https://blog.mozilla.org/security/2015/04/30/deprecating-non-secure-http/

> 
> Last but not least, when you're asking for everything to be encrypted, 
> you're missing the point of many websites. 

Are mozilla actually asking for this? I like the letsencrypt.org
accomplishments (whilst wishing they had strayed further from the
traditional CA model) but the mission statement is misguided IMO.

> Not all of them have a login. 
> Many sites are just simple plain old web pages that give information, 
> including product information and personal sites, and there's no reason 
> to encrypt them.
> 
> Please note that I'm a very strong privacy advocate. But calling a 
> normal HTTP "insecure" is just plain wrong. Sending passwords over HTTP 
> is insecure (typically, not always). Running old browsers and email 
> programs is insecure. Reading my blog unencrypted is not insecure.
> 
> Starting to flag the most common communication protocol in the world 
> "insecure", while most enterprises are using age-old browser and getting 
> hacked, is simply barking at the wrong tree.


Aren't I correct in that normal HTTP will only be called insecure if it
uses features such as htaccess passwords.

Is there a current list of what features will be blocked?

Video Card hardware acceleration being marked as insecure, might be
annoying. Click to play would be the right move.

It's stated that AES accelerated CPUs mean TLS doesn't matter but man
y clients struggle with web content already, especially on Linux/Unix
and many clients don't have intel i5 processors and actually my web
server cpu is a year too old. I know the main reason for video
struggling on Linux is Adobe's poor flash implementation but xombrero
whilst not compatible with some sites is so much quicker at loading
pages than both firefox and chrome. Perhaps the performance hit is
still marginal, but I'm certainly not convinced from my own
observations.

Incidentally, whilst I've been hoping html5 video would improve things,
the recent upgrade to itv.com has made one of my mythtv boxes in browser
video frame rate drop recently, of course TLS was used before also. I
have a windows box I can use in the same room that I use for
silverlight but that's just annoying and isn't always available.

-- 

KISSIS - Keep It Simple So It's Securable
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.