Re: Proposal: Marking HTTP As Non-Secure
Kevin Chadwick <[email protected]> Tue, 2 Feb 2016 18:39:01 +0000
| Newsgroups | gmane.comp.web.chromium.security.devel,gmane.comp.mozilla.security |
|---|---|
| Message-ID | <[email protected]> |
> The most relevant part of the article is that Comcast was modifying HTTP > traffic. The following link shows Verizon doing the same thing. These two > ISPs control a large part of the US. Given the political landscape here, > assuming that users can choose ISPs is rather unrealistic. > > http://arstechnica.com/security/2014/10/verizon-wireless-injects-identifiers-link-its-users-to-web-requests/ > > Based on the information above, the browser should tell users that HTTP is > insecure, as it exposes them to all the issues described above. > > Users can choose to ignore the warnings, if they took the steps you > outlined and trust their ISP and the entire path up to the server. For most > people though, HTTP is inadequate for any sort of browsing, because it > lacks integrity guarantees. > > Firstly this is verging off subject and certainly says little about the concerns I have raised which I feel are far more important. Should the current situation be reversed and SSL eventually become unlabelled and what social effects would that actually have?! I can understand your position but feel your statements are far over reaching atleast today and can you really not find a trustable ISP. I admit I know little of American ISPs but notice the first link was actually trying to help users but assuming corruption could take place I suppose there is some credit for commercial sabotage and bribery somewhere along the backbones, but it's not really plausible. ISPs have been known to create revenue from general advertising before and it almost happened in the UK but was squashed thankfully. So I see the point but would rather I had an ISP I could trust than one forced to behave. > > If that was part of the discussion then signing or a VPN would be a more > > appropriate answer though perhaps the payload and so bandwidth for very > > light web pages could increase even more so than encrypted in the case > > of signing. > > > > The VPN provider is yet another ISP in the chain that HTTP traffic goes > through. It can misbehave, just like all the other links in the chain. If they are getting business for not doing so then they are unlikely to. -- KISSIS - Keep It Simple So It's Securable -- You received this message because you are subscribed to the Google Groups "Security-dev" group. To unsubscribe from this group and stop receiving emails from it, send an email to [email protected]