Re: HTTP is just fine

Kevin Chadwick <[email protected]>
Newsgroups gmane.comp.mozilla.security
Message-ID <[email protected]>
> Please, explain why we should not have protections against unlikely, but 
> conceivable attacks (attacks that are either documented, or have easy to 
> use tools to facilitate them).
> 

Please explain what protections I am saying you should not have, do you
mean https everywhere. If that is what you mean then prepare yourself..
if I can be bothered to keep responding to this nonsense.

> yes, the few times you went to the coffee place and used unsecured WiFi 
> you may not have gotten your cookies sniffed and didn't get malware 
> injected into javascript (or jpg files that exploit bugs in renderers, r 
> different account numbers for wire-transfers... pick your poison)

I wouldn't use a device worth hacking on an unsecured wifi. I shall
ignore that being the case though and state that if I was on an
unsecured coffee shop network (which are rare these days) with many
users and I was a black hat then it would not matter if they were using
TLS or not as to whether I could takeover many of their machines and
probably every mobile phone!!

So I'm still struggling to see your value proposition especially when
things that need TLS will use it anyway in a secure manner??

Are you saying people shouldn't need to look for https or a padlock in
which case they still need to check the domain name which is actually
far more important, so again there is no argumwent? Will they only
check the domain name if it says insecure and so possibly making the
situation worse??

-- 

KISSIS - Keep It Simple So It's Securable
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.