Re: Proposal: Marking HTTP As Non-Secure

ianG <[email protected]> Tue, 9 Feb 2016 01:35:10 +0000
Newsgroups gmane.comp.mozilla.security
Message-ID <[email protected]>
On 8/02/2016 09:58 am, Craig Francis wrote:
> Hi Kevin,
>
> I'm more of a web developer, but my opinion is that all web traffic should have always been encrypted.

I'm curious ... Is that your opinion because you've been taught that? 
Or because you've done a risk analysis over a group of people and opined 
that the cost of encryption is worth it to them to encrypt against the 
cost of eavesdropping?

Just to declare my colours here - I don't know of too many efforts that 
have taken that second step... so .. why do we believe it should all be 
encrypted?

I'm not disagreeing.  I also believe it should be encrypted.  But, why?


> It's only because of the initial difficulties (hard server setup, processing time, etc) that this wasn't the case.


Yeah.  History really screwed us over on this one...


> Perhaps a "real world" example will explain...
>
> Take the process of sending a simple letter to someone.
>
> Would you write everything on a postcard? or would you at least put the letter in an envelope?

People choose either/both all the time.


> Most people use envelopes as a very basic/simple way to ensure the letter is not read or altered by anyone else on route... for example, you can typically tell when an envelope has been opened (ish).
>
> Unfortunately an envelope isn't as good as modern encryption (e.g. giving you any confidence that the message you received actually came from the right person).
>
> Whereas plain text HTTP is even worse than using a postcard (it's very easy to change its content, as you don't see words being crossed out, or being written in a different hand writing style).


So, the topic of metadata.  People go on holiday and send postcards. 
They're being tracked by copies.  People are trained to write their 
address on the back of envelopes.  Incoming into every country, front 
and back of every envelope is photographed.  Meta data is collected.

Which is to say, it's fine to use analogues and metaphors.  But 
actually, nobody much is doing any serious threat analysis to users in 
current day.

If they were to do that, I think they'd be shocked.


> I certainty take your point that HTTPS is currently more difficult than it needs to be, but with systems like LetsEncrypt, we will have this built into the web servers soon, and it will do all the setup by itself, you won't even need to "switch it on"... and it's at that point, we can say HTTPS is just "normal" (to the point we don't even need to show a padlock) and that anything still using plain text is simply insecure.


We need likely 10 or 100 systems like LetsEncrypt, or self-encryption, 
or both.  Then it might work.  I'm not saying today is bad, I'm saying 
we need to do much more.  And not listen to any "ivory tower" thinking.



iang