Re: HTTP is just fine -- v. HTTP is insecure --> need a better metaphor
Hubert Kario <[email protected]>
| Newsgroups | gmane.comp.mozilla.security |
|---|---|
| Message-ID | <[email protected]> |
On Thursday 26 November 2015 08:14:21 ianG wrote: > > 1)... stop widespread surveillance,... > > 2) ... It seems that the argument is just around HTTP > > being safe or unsafe, without really defining what safety is or how > > it applies to both the situation that a user is in at an exact > > moment in time or potentially at some time in the future. > > This is the problem that everyone in Mozilla is not facing up to. > > Unfortunately there's no point in entering it because without a > cultural change, you won't be able to deal with the results. > > Just one small result: your 1) is actually the worry of the developer > community, not the users. In order to figure out what users are > worried about, you'd have to ... ask them. And people did ask them and did receive responses saying "yes we want this program shut down": https://www.youtube.com/watch?v=XEVlyP4_11M you just need to ask correct question to get people to understand the issue > > These comments help to get some focus back on that area of the > > discussion/> > >>> if mozilla says my site is insecure. > >> > >> mozilla doesn't say that your site is insecure > >> > >> mozilla wants to say that the connection between the computer and > >> your> > > site is insecure > > Not really. Mozilla wants to say that the model is operating > correctly and this site is in/outside its approved model. To say > "secure" or "insecure" is to say something outside Mozilla's legal > comfort zone. > > Developers OTOH want to say it is secure or insecure. But developers > aren't responsible. The browser has insight in the protections used on the connection between it and the site. It can make automated and correct assessments of the security (integrity and confidentiality) of those connections. Firefox still doesn't say anything about the *server* being secure or not, it says "Secure Connection". This won't change. -- Regards, Hubert Kario Senior Quality Engineer, QE BaseOS Security team Web: www.cz.redhat.com Red Hat Czech s.r.o., Purkyňova 99/71, 612 45, Brno, Czech Republic _______________________________________________ dev-security mailing list [email protected] https://lists.mozilla.org/listinfo/dev-security
signature.asc
(application/pgp-signature, 819 B)
-----BEGIN PGP SIGNATURE----- Version: GnuPG v2 iQIcBAABCgAGBQJWVu8XAAoJEJKo0bgB0vX1aqQQAJ+Wj4w/bF992PX96ovaRXJ9 Bd6JVOkBFGZ7fkn5S4Hthc9QLXsfP5AMdA+/zBFMJ/c/AOfbpUY/Wy3YxqC9Ov8x IsawK4oicPLEUUse7rocTZzPWsvgjn3F6KpthLxFila3wMDkiE76ynoCQtXNrtvG 96uBYzZFZlbZTznOoDBIljiLu6R8XiPG5xl2LvC2GWbHXfCnLj8c3gv+agjjHRYf VokdpyX2NJXFQpGi/RqWWTCUm0c6xsyN3fuWlLQOsi6V8DJRC3imLyN5p29+fvoq Sv3wuPeMXTLnlgobcIQVbghvqjOjqOSRReufMeCiAZj40QOG0XuySA9RA3ZYR1ED JXYOWk9HwTaeaPMRwGlgDpOFs1B4HgkdpsLxY4xjDymI1c61tXhog+o7Eb1lcwwN 3SBm+RKEn4Nv8dFXHg+ADwpXF2nnM9IQkG5CK+2vv2aO40XMisGIvur1buYR+o/x kdt9Q4ho0z+7rD7+5rC6CywD5YQxZ0mg80Z7pgTCwJkGi43T0XYuXQFCZwEvaQUo 1jBzg8iS2AQCpu7e7N0m49I/iLDQuYzy0hgvvZYsmnpQNmmO7YmZHPbyyUz303yn nojIFgho+HMr4Grnxidb5iktpjN0K5bsJUX+HlZWSPLi2ktUK8PMb8CAhvOzpF88 8vUJn0pqP7rUk357V4wx =U1SG -----END PGP SIGNATURE-----