Re: HTTP is just fine -- v. HTTP is insecure --> need a better metaphor

Hubert Kario <[email protected]>
Newsgroups gmane.comp.mozilla.security
Message-ID <[email protected]>
On Thursday 26 November 2015 08:14:21 ianG wrote:
> > 1)... stop widespread surveillance,...
> > 2) ...   It seems that the argument is just around HTTP
> > being safe or unsafe, without really defining what safety is or how
> > it applies to both the situation that a user is in at an exact
> > moment in time or potentially at some time in the future.
> 
> This is the problem that everyone in Mozilla is not facing up to.
> 
> Unfortunately there's no point in entering it because without a
> cultural change, you won't be able to deal with the results.
> 
> Just one small result:  your 1) is actually the worry of the developer
> community, not the users.  In order to figure out what users are
> worried about, you'd have to ... ask them.

And people did ask them and did receive responses saying "yes we want 
this program shut down":
https://www.youtube.com/watch?v=XEVlyP4_11M

you just need to ask correct question to get people to understand the 
issue

> > These comments help to get some focus back on that area of the
> > discussion/> 
> >>> if mozilla says my site is insecure.
> >> 
> >> mozilla doesn't say that your site is insecure
> >> 
> >> mozilla wants to say that the connection between the computer and
> >> your> 
> > site is insecure
> 
> Not really.  Mozilla wants to say that the model is operating
> correctly and this site is in/outside its approved model.  To say
> "secure" or "insecure" is to say something outside Mozilla's legal
> comfort zone.
> 
> Developers OTOH want to say it is secure or insecure.  But developers
> aren't responsible.

The browser has insight in the protections used on the connection 
between it and the site. It can make automated and correct assessments 
of the security (integrity and confidentiality) of those connections.

Firefox still doesn't say anything about the *server* being secure or 
not, it says "Secure Connection". This won't change.

-- 
Regards,
Hubert Kario
Senior Quality Engineer, QE BaseOS Security team
Web: www.cz.redhat.com
Red Hat Czech s.r.o., Purkyňova 99/71, 612 45, Brno, Czech Republic

_______________________________________________
dev-security mailing list
[email protected]
https://lists.mozilla.org/listinfo/dev-security
signature.asc (application/pgp-signature, 819 B)
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2

iQIcBAABCgAGBQJWVu8XAAoJEJKo0bgB0vX1aqQQAJ+Wj4w/bF992PX96ovaRXJ9
Bd6JVOkBFGZ7fkn5S4Hthc9QLXsfP5AMdA+/zBFMJ/c/AOfbpUY/Wy3YxqC9Ov8x
IsawK4oicPLEUUse7rocTZzPWsvgjn3F6KpthLxFila3wMDkiE76ynoCQtXNrtvG
96uBYzZFZlbZTznOoDBIljiLu6R8XiPG5xl2LvC2GWbHXfCnLj8c3gv+agjjHRYf
VokdpyX2NJXFQpGi/RqWWTCUm0c6xsyN3fuWlLQOsi6V8DJRC3imLyN5p29+fvoq
Sv3wuPeMXTLnlgobcIQVbghvqjOjqOSRReufMeCiAZj40QOG0XuySA9RA3ZYR1ED
JXYOWk9HwTaeaPMRwGlgDpOFs1B4HgkdpsLxY4xjDymI1c61tXhog+o7Eb1lcwwN
3SBm+RKEn4Nv8dFXHg+ADwpXF2nnM9IQkG5CK+2vv2aO40XMisGIvur1buYR+o/x
kdt9Q4ho0z+7rD7+5rC6CywD5YQxZ0mg80Z7pgTCwJkGi43T0XYuXQFCZwEvaQUo
1jBzg8iS2AQCpu7e7N0m49I/iLDQuYzy0hgvvZYsmnpQNmmO7YmZHPbyyUz303yn
nojIFgho+HMr4Grnxidb5iktpjN0K5bsJUX+HlZWSPLi2ktUK8PMb8CAhvOzpF88
8vUJn0pqP7rUk357V4wx
=U1SG
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.