Re: Proposal: Marking HTTP As Non-Secure

Kevin Chadwick <[email protected]> Sun, 31 Jan 2016 22:23:23 +0000
Newsgroups gmane.comp.mozilla.security
Message-ID <[email protected]>
> And so now email is "sensitive" because of a combination of proactive and
> reactive leadership that changed the status quo. I don't remember feeling
> annoyed or worried about my webmail being served over plain HTTP in 2008. I
> didn't "accept" the security limitations -- I didn't understand them. Other
> people had to realize on my behalf that I was in danger, and I am glad that
> they did.
>

So long as you understand that email is still not secure today without
PGP/GPG. Otherwise a false sense of security is worse than no security
springs to mind.

Of course it is better that it is harder to get control of someones box
as oppose to reading some of todays mail due to flaws in STARTTLS and
also the domain system.

Unfortunately until DNSSEC/DANE becomes useful that likely won't
change. Perhaps there really is more use for DNSCURVE.

 
> You may personally accept HTTP's security limitations, but that doesn't
> mean anyone is obligated to serve you plain HTTP, and it doesn't mean
> anyone ethically has to refrain from strongly incentivizing websites to
> give users the security they deserve.

Well that is debateable depending on what exactly strongly
incentivising websites means.


>> There is little inherently "broken" about HTTP (without the "S").  It has security limitations which it's audience accepts.  Over the years people have been trained to look for proactive signs of security (https, green lock, etc) when they are doing activities that are sensitive (email, banking transactions, etc).  

>>> There is a ton of UI/UX research that people do not notice the absence
>>> of positive indicators.  One can train as much as they want, but the
>>> training has not worked to date.

Well they still need to be trained to check the domain name, so that
argument is a waste of everyones time. I also disagree that the
training doesn't work. It is just many aren't trained at all.

In fact Google whilst being rightly praised for their gmail over SSL
despite potentially giving a false sense of security have a lot to
answer for in terms of encouraging users to see the url bar as a search
tool rather than a security tool or indicator of who they are
communicating with!!

-- 

KISSIS - Keep It Simple So It's Securable