Re: Proposal: Marking HTTP As Non-Secure

Victor Costan <[email protected]> Tue, 2 Feb 2016 10:20:13 -0500
Newsgroups gmane.comp.web.chromium.security.devel,gmane.comp.mozilla.security
Message-ID <CALFbkGX8if3asv+qmbm7GVv=NSoSQ+_EJcfjR5f5LeFfmeHTwA@mail.gmail.com>
On Tue, Feb 2, 2016 at 11:13 AM, Kevin Chadwick <[email protected]> wrote:

> > > If however you mainly do research of public domain content that has no
> > > need to be encrypted or I expect most things on the internet have no
> > > need to be encrypted then it seems more important to say to users:
> > >
> > > Hey as this sites admin I have decided that this communication needs
> > > to be secure therefore you should check the domain name is correct.
> > >
> >
> >
> > Equating HTTPS to encryption, and therefore privacy guarantees, is
> > incorrect. HTTPS also gives you integrity guarantees. My site contents
> may
> > be public, but I'd prefer to be assured that users get exactly what I
> > wrote, without any additions or edits from other parties on the network.
> >
> > For an example why these concerns are legitimate, see
> >
> http://arstechnica.com/tech-policy/2014/09/why-comcasts-javascript-ad-injections-threaten-security-net-neutrality/
>
> I don't see how WIFI hotspots have anything to do with the discussion
> and your network provider, backbone and YOUR server location choices
> should be more responsible.
>

The most relevant part of the article is that Comcast was modifying HTTP
traffic. The following link shows Verizon doing the same thing. These two
ISPs control a large part of the US. Given the political landscape here,
assuming that users can choose ISPs is rather unrealistic.

http://arstechnica.com/security/2014/10/verizon-wireless-injects-identifiers-link-its-users-to-web-requests/

Based on the information above, the browser should tell users that HTTP is
insecure, as it exposes them to all the issues described above.

Users can choose to ignore the warnings, if they took the steps you
outlined and trust their ISP and the entire path up to the server. For most
people though, HTTP is inadequate for any sort of browsing, because it
lacks integrity guarantees.


> If that was part of the discussion then signing or a VPN would be a more
> appropriate answer though perhaps the payload and so bandwidth for very
> light web pages could increase even more so than encrypted in the case
> of signing.
>

The VPN provider is yet another ISP in the chain that HTTP traffic goes
through. It can misbehave, just like all the other links in the chain.

    Victor

-- 
You received this message because you are subscribed to the Google Groups "Security-dev" group.
To unsubscribe from this group and stop receiving emails from it, send an email to [email protected]