Re: Proposal: Marking HTTP As Non-Secure
Kevin Chadwick <[email protected]> Tue, 2 Feb 2016 21:09:16 +0000
| Newsgroups | gmane.comp.web.chromium.security.devel,gmane.comp.mozilla.security |
|---|---|
| Message-ID | <[email protected]> |
> The debate of "what should be encrypted" has already been had on this > mailing list, and many other lists multiple times. I think it would be best > to research and read up on those before proposing ideas of what information > is "sensitive" and what information isn't, as those topics have already > been fully fleshed out and put on the table. I didn't really bring that up I just pointed the flaws out on what you brought up orthogonally to justify this proposal! The point I was making was that the still standing proposal page still indicates that it has clearly currently still not been thought through. The page does not say we will warn users if they are going to submit data. Crying wolf on every http page is more likely to desensitise users but there is some potential merit. I don't believe the masses will listen to google and enforce SSL everywhere and the evidence suggests justs that. I believe they shouldn't do so too but that has little to do with my point. The current situation does mean that right now and for the forseeable future, desensitisation to warnings as a result may be significant. Therfore the current proposal could do far more harm than good. T0 (now): Non-secure origins unmarked T1: Non-secure origins marked as Dubious T2: Non-secure origins marked as Non-secure T3: Secure origins unmarked ^^^^^^^^^^^^^ On top of that the ill thought bias is demonstrated further because not indicating SSL on the "expected" majority of pages removes a valid prompt to users who will likely think, ooh this is different. I should handle this more carefully. The unknown is always handled with more care, that is a fact. The current SSL interactions are poor, removing them completely is worse IMO. Anyway I shan't respond again, I believe some of this may have been brought up before but I guess the proposal hasn't changed unless there is a new page or maybe internally. Someone obviously got overly carried away with their "LetsEncrypt" mantra when considering that proposal on that webpage as it stands. -- KISSIS - Keep It Simple So It's Securable -- You received this message because you are subscribed to the Google Groups "Security-dev" group. To unsubscribe from this group and stop receiving emails from it, send an email to [email protected]