Re: HTTP is just fine

Hubert Kario <[email protected]>
Newsgroups gmane.comp.mozilla.security
Message-ID <[email protected]>
On Wednesday 25 November 2015 16:07:10 Kevin Chadwick wrote:
> it's getting tiresome when the same bull keeps being
> repeated on the same topic on the same list without included
> justification that has had any consideration or time spent
> and at the same time the opposite is stated whimsically and very
> strongly yet incorrectly with the intention of stopping responses.
>
> Anyway, I give up, some people obviously have irremovable filters on
> their brains

"funny" you say that, I have exact same feelings

> if mozilla say my site is insecure.

mozilla doesn't say that your site is insecure

mozilla wants to say that the connection between the computer and your 
site is insecure

> I shall simply tell
> customers that it is more secure than mozilla.com and mozilla are dumb
> and believe that they will believe me.

and again with the ad hominems... I seriously wonder why I'm even 
bothering at this point


Please, explain why we should not have protections against unlikely, but 
conceivable attacks (attacks that are either documented, or have easy to 
use tools to facilitate them).

yes, the few times you went to the coffee place and used unsecured WiFi 
you may not have gotten your cookies sniffed and didn't get malware 
injected into javascript (or jpg files that exploit bugs in renderers, r 
different account numbers for wire-transfers... pick your poison)

you may live in a place where your ISP doesn't want to get few extra 
pennies by replacing ads on pages you watch, and you may not have 
neighbours that try to sniff credit card numbers (or SSNs) from 
connections that go through the shared cable TV network

you may even leave your doors unlocked because you live in a house in 
the middle of a prairie

or live in a city and forgot to close the doors few times and nothing 
bad happened

are you really trying to say that because of that few instances we all 
should leave our doors unlocked and boycott insurance companies that 
expect you to lock your homes?

that because there are other technologies for securing communications we 
shouldn't use the one that is easiest to use by normal users? one that 
does not require any additional setup by the users?
-- 
Regards,
Hubert Kario
Senior Quality Engineer, QE BaseOS Security team
Web: www.cz.redhat.com
Red Hat Czech s.r.o., Purkyňova 99/71, 612 45, Brno, Czech Republic

_______________________________________________
dev-security mailing list
[email protected]
https://lists.mozilla.org/listinfo/dev-security
signature.asc (application/pgp-signature, 819 B)
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2

iQIcBAABCgAGBQJWVebtAAoJEJKo0bgB0vX15N0P/0VXiOZPa8igBHm11T2BSP7P
lh7h4seUg5shDwkQwuNBPXLkXfi5ZCwBntwrSQbuo/NfPSLOPS9tL/DlNmfeaGNW
e/CibsuuVm4izpSpxzBe/X81Om7i/Py7B/A/P8bxqD5ScGsBviFi10Wnq+Cmk2b1
AoRhfYGVBU5evcw1xUynyzULVvTbhUC0OcUuprFHYMQlj8NSG2oc35aSf09tSxJs
rQK/o/tvU+/UelwvkbN3jWy9FVqmil3v6MAcxtL8+4cwoZwtxvgcPfiqSVMUxp9+
dpTvv2Biy2B8KyiEpG/aYiH8boatgsMjcj4lGy5JiscF6dzOC6iY69raqUdiaBSY
bQzwc0lz2r6koqInW++DFrkNVcM7zwDgPGlBV+7SpURf8JfGAaoloEZjT4kY0zPX
PE/krAkGa/pz1jcUjf/6atZPYbBmbCXAbOICJ2IfiiijJyFk9LVAN4uGMCaSLQTE
mioo0QvRX5Pg4xMI7xdgFV8Ma/6LjzBSGUJ0L/6EpojaAgoC7DeDBZHD9QFcd+jD
doxEuIp8qUiVR8VfNIhzqGuAbGW/Qgq2XDtfoMDowfC9XdDYEpoEAQrKAiExxRA+
U/MXdP8qmrpla4uCtitSXEgE2R5S5rf99ffAQ9aNd6hFWLQkjUazVi668gUEE6N/
ZD0yKTvV7d0nshTVA4cv
=yTiw
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.