Re: Proposal: Marking HTTP As Non-Secure
Vincent Lynch <[email protected]> Tue, 2 Feb 2016 12:48:53 -0500
| Newsgroups | gmane.comp.web.chromium.security.devel,gmane.comp.mozilla.security |
|---|---|
| Message-ID | <CAM_pNrdsbVDYNSSZciCd5szLk8Psqr9Z5YAs_xsJQPzqFWc31g@mail.gmail.com> |
Hello Kevin, I will admit I do not fully understand what you are arguing for, but to address the topic of ISP choice: There are many users around the world who do not have a choice. There are multiple reasons this may occur. Perhaps there is a regional monopoly or all Internet access is regulated/controlled by the government. Maybe they are on a plane and need Internet access, but only one provider exists on any given flight. Maybe they are at work and have no ability to decide what ISP the office uses. But, It does not really matter why they don't have a choice. Any solution that relies on a user changing their ISP is unrealistic and far too large of a choice to ask an everyday person to make. Furthermore, while I do not want to discourage discussion, I think this entire discussion is off topic. The original question raised in this thread was: "what is the status of [the proposal to mark HTTP as insecure]?" The answer is (as far as I'm aware...) that Google continues to pursue this goal, but has no firm dates on when this will happen. A general outline was proposed with the original policy that suggests non-secure origins will be marked as "dubious" (which means an indicator that is "softer" than the red-x) MAY occur when secure traffic reaches a 65% share of an avg user's interaction with the web. The debate of "what should be encrypted" has already been had on this mailing list, and many other lists multiple times. I think it would be best to research and read up on those before proposing ideas of what information is "sensitive" and what information isn't, as those topics have already been fully fleshed out and put on the table. -Vincent On Tuesday, February 2, 2016, Kevin Chadwick <[email protected]> wrote: > > The most relevant part of the article is that Comcast was modifying HTTP > > traffic. The following link shows Verizon doing the same thing. These two > > ISPs control a large part of the US. Given the political landscape here, > > assuming that users can choose ISPs is rather unrealistic. > > > > > http://arstechnica.com/security/2014/10/verizon-wireless-injects-identifiers-link-its-users-to-web-requests/ > > > > Based on the information above, the browser should tell users that HTTP > is > > insecure, as it exposes them to all the issues described above. > > > > Users can choose to ignore the warnings, if they took the steps you > > outlined and trust their ISP and the entire path up to the server. For > most > > people though, HTTP is inadequate for any sort of browsing, because it > > lacks integrity guarantees. > > > > > > Firstly this is verging off subject and certainly says little about > the concerns I have raised which I feel are far more important. Should > the current situation be reversed and SSL eventually become unlabelled > and what social effects would that actually have?! > > I can understand your position but feel your statements are far over > reaching atleast today and can you really not find a trustable ISP. I > admit I know little of American ISPs but notice the first link was > actually trying to help users but assuming corruption could take place > I suppose there is some credit for commercial sabotage and bribery > somewhere along the backbones, but it's not really plausible. > > ISPs have been known to create revenue from general advertising before > and it almost happened in the UK but was squashed thankfully. So I see > the point but would rather I had an ISP I could trust than one forced to > behave. > > > > > If that was part of the discussion then signing or a VPN would be a > more > > > appropriate answer though perhaps the payload and so bandwidth for very > > > light web pages could increase even more so than encrypted in the case > > > of signing. > > > > > > > The VPN provider is yet another ISP in the chain that HTTP traffic goes > > through. It can misbehave, just like all the other links in the chain. > > If they are getting business for not doing so then they are unlikely to. > > -- > > KISSIS - Keep It Simple So It's Securable > > -- > You received this message because you are subscribed to the Google Groups > "Security-dev" group. > To unsubscribe from this group and stop receiving emails from it, send an > email to [email protected] <javascript:;>. > > -- Vincent Lynch -- You received this message because you are subscribed to the Google Groups "Security-dev" group. To unsubscribe from this group and stop receiving emails from it, send an email to [email protected]