Re: HTTP is just fine
Kevin Chadwick <[email protected]>
| Newsgroups | gmane.comp.mozilla.security |
|---|---|
| Message-ID | <[email protected]> |
> Please, explain why we should not have protections against unlikely, but > conceivable attacks (attacks that are either documented, or have easy to > use tools to facilitate them). > Please explain what protections I am saying you should not have, do you mean https everywhere. If that is what you mean then prepare yourself.. if I can be bothered to keep responding to this nonsense. > yes, the few times you went to the coffee place and used unsecured WiFi > you may not have gotten your cookies sniffed and didn't get malware > injected into javascript (or jpg files that exploit bugs in renderers, r > different account numbers for wire-transfers... pick your poison) I wouldn't use a device worth hacking on an unsecured wifi. I shall ignore that being the case though and state that if I was on an unsecured coffee shop network (which are rare these days) with many users and I was a black hat then it would not matter if they were using TLS or not as to whether I could takeover many of their machines and probably every mobile phone!! So I'm still struggling to see your value proposition especially when things that need TLS will use it anyway in a secure manner?? Are you saying people shouldn't need to look for https or a padlock in which case they still need to check the domain name which is actually far more important, so again there is no argumwent? Will they only check the domain name if it says insecure and so possibly making the situation worse?? -- KISSIS - Keep It Simple So It's Securable