Re: Proposal: Marking HTTP As Non-Secure

Craig Francis <[email protected]> Mon, 8 Feb 2016 09:58:00 +0000
Newsgroups gmane.comp.mozilla.security
Message-ID <[email protected]>
Hi Kevin,

I'm more of a web developer, but my opinion is that all web traffic should have always been encrypted.

It's only because of the initial difficulties (hard server setup, processing time, etc) that this wasn't the case.

Perhaps a "real world" example will explain...

Take the process of sending a simple letter to someone.

Would you write everything on a postcard? or would you at least put the letter in an envelope?

Most people use envelopes as a very basic/simple way to ensure the letter is not read or altered by anyone else on route... for example, you can typically tell when an envelope has been opened (ish).

Unfortunately an envelope isn't as good as modern encryption (e.g. giving you any confidence that the message you received actually came from the right person).

Whereas plain text HTTP is even worse than using a postcard (it's very easy to change its content, as you don't see words being crossed out, or being written in a different hand writing style).

I certainty take your point that HTTPS is currently more difficult than it needs to be, but with systems like LetsEncrypt, we will have this built into the web servers soon, and it will do all the setup by itself, you won't even need to "switch it on"... and it's at that point, we can say HTTPS is just "normal" (to the point we don't even need to show a padlock) and that anything still using plain text is simply insecure.

Craig




On 7 Feb 2016, at 22:23, Kevin Chadwick <[email protected]> wrote:

>> This is demonstrability unhelpful.  UI/UX research has shown
>> consistently that people do not notice the absence of positive
>> indicators.
>> 
>> Some things to read:
>> - Trust Me: Design Patterns for Constructing Trustworthy Trust Indicators
>> - The emperor’s new security indicators in Proceedings of the 2007
>> IEEE Symposium on Security and Privacy,.
>> - Use of Visual Security Cues in Web Browsers in Proceedings of the
>> 2005 Conference on Graphics Interface
> 
> So, are you against the proposal then?
> 
> I am, reversing the original design is simply ridiculous.
> 
> -- 
> 
> KISSIS - Keep It Simple So It's Securable
> 
> -- 
> You received this message because you are subscribed to the Google Groups "Security-dev" group.
> To unsubscribe from this group and stop receiving emails from it, send an email to [email protected].
> 
_______________________________________________
dev-security mailing list
[email protected]
https://lists.mozilla.org/listinfo/dev-security