Re: HTTP is just fine -- v. HTTP is insecure --> need a better metaphor
ianG <[email protected]>
| Newsgroups | gmane.comp.mozilla.security |
|---|---|
| Message-ID | <[email protected]> |
On 26/11/2015 11:37 am, Hubert Kario wrote: > On Thursday 26 November 2015 08:14:21 ianG wrote: >>> 1)... stop widespread surveillance,... >>> 2) ... It seems that the argument is just around HTTP >>> being safe or unsafe, without really defining what safety is or how >>> it applies to both the situation that a user is in at an exact >>> moment in time or potentially at some time in the future. >> >> This is the problem that everyone in Mozilla is not facing up to. >> >> Unfortunately there's no point in entering it because without a >> cultural change, you won't be able to deal with the results. >> >> Just one small result: your 1) is actually the worry of the developer >> community, not the users. In order to figure out what users are >> worried about, you'd have to ... ask them. > > And people did ask them and did receive responses saying "yes we want > this program shut down": > https://www.youtube.com/watch?v=XEVlyP4_11M :) great show. That was worth watching *all the way through* ! > you just need to ask correct question to get people to understand the > issue Right. That guy knows how to frame things, he should be in security :) Along those lines, asking whether people are worried about mass surveillance is going to walk into some cultural artifacts. In Europe for example, the general feeling is more about government protecting the people, so mass surveillance is more expected. What they fear is corporate surveillance. Whereas Americans tend to be the reverse. Then, if you go to various other quarters like Africa which is now mobile-enabled, they won't understand the question (unless they are western educated). It will be something between "well of course!" or "err..." or "how does this effect battery life?" Point being, you have to get down and dirty to find out what is really worrying people. And whether you can help. If you pick your threat models from your circle of people, you've already lost. >>> These comments help to get some focus back on that area of the >>> discussion/> >>>>> if mozilla says my site is insecure. >>>> >>>> mozilla doesn't say that your site is insecure >>>> >>>> mozilla wants to say that the connection between the computer and >>>> your> >>> site is insecure >> >> Not really. Mozilla wants to say that the model is operating >> correctly and this site is in/outside its approved model. To say >> "secure" or "insecure" is to say something outside Mozilla's legal >> comfort zone. >> >> Developers OTOH want to say it is secure or insecure. But developers >> aren't responsible. > > The browser has insight in the protections used on the connection > between it and the site. It can make automated and correct assessments > of the security (integrity and confidentiality) of those connections. > > Firefox still doesn't say anything about the *server* being secure or > not, it says "Secure Connection". This won't change. We are in full agreement. Firefox does secure connections. Within a security model (assumptions). What Firefox doesn't do is security. Security is something different. Security is what users need. In the context of that above video, SnapChat gets it right. iang