Re: Proposal: Marking HTTP As Non-Secure

Kevin Chadwick <[email protected]> Tue, 2 Feb 2016 21:09:16 +0000
Newsgroups gmane.comp.web.chromium.security.devel,gmane.comp.mozilla.security
Message-ID <[email protected]>
> The debate of "what should be encrypted" has already been had on this
> mailing list, and many other lists multiple times. I think it would be best
> to research and read up on those before proposing ideas of what information
> is "sensitive" and what information isn't, as those topics have already
> been fully fleshed out and put on the table.

I didn't really bring that up I just pointed the flaws out on what you
brought up orthogonally to justify this proposal!

The point I was making was that the still standing proposal page
still indicates that it has clearly currently still not been thought
through.

The page does not say we will warn users if they are going to submit
data.

Crying wolf on every http page is more likely to desensitise users but
there is some potential merit. I don't believe the masses will listen
to google and enforce SSL everywhere and the evidence suggests justs
that. I believe they shouldn't do so too but that has little to do with
my point. The current situation does mean that right now and for the
forseeable future, desensitisation to warnings as a result may be
significant. Therfore the current proposal could do far more harm than
good.

T0 (now): Non-secure origins unmarked
T1: Non-secure origins marked as Dubious
T2: Non-secure origins marked as Non-secure
T3: Secure origins unmarked
		^^^^^^^^^^^^^

On top of that the ill thought bias is demonstrated further because not
indicating SSL on the "expected" majority of pages removes a valid
prompt to users who will likely think, ooh this is different. I should
handle this more carefully.

The unknown is always handled with more care, that is a fact.

The current SSL interactions are poor, removing them completely is
worse IMO.

Anyway I shan't respond again, I believe some of this may have been
brought up before but I guess the proposal hasn't changed unless there
is a new page or maybe internally. Someone obviously got overly carried
away with their "LetsEncrypt" mantra when considering that proposal on
that webpage as it stands.

-- 

KISSIS - Keep It Simple So It's Securable

-- 
You received this message because you are subscribed to the Google Groups "Security-dev" group.
To unsubscribe from this group and stop receiving emails from it, send an email to [email protected]