Re: Proposal: Marking HTTP As Non-Secure

Kevin Chadwick <[email protected]> Tue, 2 Feb 2016 16:13:04 +0000
Newsgroups gmane.comp.web.chromium.security.devel,gmane.comp.mozilla.security
Message-ID <[email protected]>
> > If however you mainly do research of public domain content that has no
> > need to be encrypted or I expect most things on the internet have no
> > need to be encrypted then it seems more important to say to users:
> >
> > Hey as this sites admin I have decided that this communication needs
> > to be secure therefore you should check the domain name is correct.
> >  
> 
> 
> Equating HTTPS to encryption, and therefore privacy guarantees, is
> incorrect. HTTPS also gives you integrity guarantees. My site contents may
> be public, but I'd prefer to be assured that users get exactly what I
> wrote, without any additions or edits from other parties on the network.
> 
> For an example why these concerns are legitimate, see
> http://arstechnica.com/tech-policy/2014/09/why-comcasts-javascript-ad-injections-threaten-security-net-neutrality/

I don't see how WIFI hotspots have anything to do with the discussion
and your network provider, backbone and YOUR server location choices
should be more responsible.

If that was part of the discussion then signing or a VPN would be a more
appropriate answer though perhaps the payload and so bandwidth for very
light web pages could increase even more so than encrypted in the case
of signing.

p.s. A wifi hotspot could also insist you accept their certificate in
order to use their bandwidth for all https which would be even worse.

p.p.s. Javascript controls in browsers are awful and sites are running
rampant in this regard!

-- 

KISSIS - Keep It Simple So It's Securable

-- 
You received this message because you are subscribed to the Google Groups "Security-dev" group.
To unsubscribe from this group and stop receiving emails from it, send an email to [email protected]