Re: Proposal: Marking HTTP As Non-Secure

Vincent Lynch <[email protected]> Tue, 2 Feb 2016 12:48:53 -0500
Newsgroups gmane.comp.web.chromium.security.devel,gmane.comp.mozilla.security
Message-ID <CAM_pNrdsbVDYNSSZciCd5szLk8Psqr9Z5YAs_xsJQPzqFWc31g@mail.gmail.com>
Hello Kevin,

I will admit I do not fully understand what you are arguing for, but to
address the topic of ISP choice:

There are many users around the world who do not have a choice. There are
multiple reasons this may occur. Perhaps there is a regional monopoly or
all Internet access is regulated/controlled by the government. Maybe they
are on a plane and need Internet access, but only one provider exists on
any given flight. Maybe they are at work and have no ability to decide what
ISP the office uses.

But, It does not really matter why they don't have a choice. Any solution
that relies on a user changing their ISP is unrealistic and far too large
of a choice to ask an everyday person to make.

Furthermore, while I do not want to discourage discussion, I think this
entire discussion is off topic. The original question raised in this thread
was: "what is the status of [the proposal to mark HTTP as insecure]?"

The answer is (as far as I'm aware...) that Google continues to pursue this
goal, but has no firm dates on when this will happen. A general outline was
proposed with the original policy that suggests non-secure origins will be
marked as "dubious" (which means an indicator that is "softer" than the
red-x) MAY occur when secure traffic reaches a 65% share of an
avg user's interaction with the web.

The debate of "what should be encrypted" has already been had on this
mailing list, and many other lists multiple times. I think it would be best
to research and read up on those before proposing ideas of what information
is "sensitive" and what information isn't, as those topics have already
been fully fleshed out and put on the table.

-Vincent
On Tuesday, February 2, 2016, Kevin Chadwick <[email protected]> wrote:

> > The most relevant part of the article is that Comcast was modifying HTTP
> > traffic. The following link shows Verizon doing the same thing. These two
> > ISPs control a large part of the US. Given the political landscape here,
> > assuming that users can choose ISPs is rather unrealistic.
> >
> >
> http://arstechnica.com/security/2014/10/verizon-wireless-injects-identifiers-link-its-users-to-web-requests/
> >
> > Based on the information above, the browser should tell users that HTTP
> is
> > insecure, as it exposes them to all the issues described above.
> >
> > Users can choose to ignore the warnings, if they took the steps you
> > outlined and trust their ISP and the entire path up to the server. For
> most
> > people though, HTTP is inadequate for any sort of browsing, because it
> > lacks integrity guarantees.
> >
> >
>
> Firstly this is verging off subject and certainly says little about
> the concerns I have raised which I feel are far more important. Should
> the current situation be reversed and SSL eventually become unlabelled
> and what social effects would that actually have?!
>
> I can understand your position but feel your statements are far over
> reaching atleast today and can you really not find a trustable ISP. I
> admit I know little of American ISPs but notice the first link was
> actually trying to help users but assuming corruption could take place
> I suppose there is some credit for commercial sabotage and bribery
> somewhere along the backbones, but it's not really plausible.
>
> ISPs have been known to create revenue from general advertising before
> and it almost happened in the UK but was squashed thankfully. So I see
> the point but would rather I had an ISP I could trust than one forced to
> behave.
>
>
> > > If that was part of the discussion then signing or a VPN would be a
> more
> > > appropriate answer though perhaps the payload and so bandwidth for very
> > > light web pages could increase even more so than encrypted in the case
> > > of signing.
> > >
> >
> > The VPN provider is yet another ISP in the chain that HTTP traffic goes
> > through. It can misbehave, just like all the other links in the chain.
>
> If they are getting business for not doing so then they are unlikely to.
>
> --
>
> KISSIS - Keep It Simple So It's Securable
>
> --
> You received this message because you are subscribed to the Google Groups
> "Security-dev" group.
> To unsubscribe from this group and stop receiving emails from it, send an
> email to [email protected] <javascript:;>.
>
>

-- 
Vincent Lynch

-- 
You received this message because you are subscribed to the Google Groups "Security-dev" group.
To unsubscribe from this group and stop receiving emails from it, send an email to [email protected]