Re: HTTP is just fine -- v. HTTP is insecure --> need a better metaphor

ianG <[email protected]>
Newsgroups gmane.comp.mozilla.security
Message-ID <[email protected]>
On 25/11/2015 19:51 pm, Chris Hofmann wrote:
> I'm sad to see a level of frustration so high that people are wanting to
> give up on this discussion.

Yeah.  But it's Mozilla's fault - not the people's.

> 1)... stop widespread surveillance,...
> 2) ...   It seems that the argument is just around HTTP
> being safe or unsafe, without really defining what safety is or how it
> applies to both the situation that a user is in at an exact moment in time
> or potentially at some time in the future.


This is the problem that everyone in Mozilla is not facing up to.

Unfortunately there's no point in entering it because without a cultural 
change, you won't be able to deal with the results.

Just one small result:  your 1) is actually the worry of the developer 
community, not the users.  In order to figure out what users are worried 
about, you'd have to ... ask them.

And if they told you something different to what the developers wanted, 
then what?

Mozilla are spectacularly ill-equipped to ask that question - without a 
cultural change internally which actually goes as far as (say) changing 
the manifesto, Mozilla is locked out of that game.


> These comments help to get some focus back on that area of the discussion/
>
>>> if mozilla says my site is insecure.
>
>> mozilla doesn't say that your site is insecure
>
>> mozilla wants to say that the connection between the computer and your
> site is insecure


Not really.  Mozilla wants to say that the model is operating correctly 
and this site is in/outside its approved model.  To say "secure" or 
"insecure" is to say something outside Mozilla's legal comfort zone.

Developers OTOH want to say it is secure or insecure.  But developers 
aren't responsible.


> Exactly.  Just as it would be inappropriate for an alarm in my car to go
> off if I pull out of the driveway without my seatbelt attaached, and an
> alarm tried to communcate "you don't have your seatbelt attached, your're
> going crash and kill yourself"  It would not be appropriate to over (or
> under) communcate about the exact risks you are currently encountering.
> These things are more to the truth.


All analogies are good until they are not.  If one is to apply that to 
the situation, the mistake might be analogised as - yes, you are 
supplying seats with seatbelts, and they are very good seats and 
fantastically safe seatbelts.  But have you noticed that the seatbelt 
design assumed cars, and you don't actually supply seats to cars?

So who do you supply seats to?  And what might make *them* safer?

iang
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.