Re: Proposal: Marking HTTP As Non-Secure
Kevin Chadwick <[email protected]> Sun, 31 Jan 2016 22:23:23 +0000
| Newsgroups | gmane.comp.mozilla.security |
|---|---|
| Message-ID | <[email protected]> |
> And so now email is "sensitive" because of a combination of proactive and > reactive leadership that changed the status quo. I don't remember feeling > annoyed or worried about my webmail being served over plain HTTP in 2008. I > didn't "accept" the security limitations -- I didn't understand them. Other > people had to realize on my behalf that I was in danger, and I am glad that > they did. > So long as you understand that email is still not secure today without PGP/GPG. Otherwise a false sense of security is worse than no security springs to mind. Of course it is better that it is harder to get control of someones box as oppose to reading some of todays mail due to flaws in STARTTLS and also the domain system. Unfortunately until DNSSEC/DANE becomes useful that likely won't change. Perhaps there really is more use for DNSCURVE. > You may personally accept HTTP's security limitations, but that doesn't > mean anyone is obligated to serve you plain HTTP, and it doesn't mean > anyone ethically has to refrain from strongly incentivizing websites to > give users the security they deserve. Well that is debateable depending on what exactly strongly incentivising websites means. >> There is little inherently "broken" about HTTP (without the "S"). It has security limitations which it's audience accepts. Over the years people have been trained to look for proactive signs of security (https, green lock, etc) when they are doing activities that are sensitive (email, banking transactions, etc). >>> There is a ton of UI/UX research that people do not notice the absence >>> of positive indicators. One can train as much as they want, but the >>> training has not worked to date. Well they still need to be trained to check the domain name, so that argument is a waste of everyones time. I also disagree that the training doesn't work. It is just many aren't trained at all. In fact Google whilst being rightly praised for their gmail over SSL despite potentially giving a false sense of security have a lot to answer for in terms of encouraging users to see the url bar as a search tool rather than a security tool or indicator of who they are communicating with!! -- KISSIS - Keep It Simple So It's Securable