Re: Proposal: Marking HTTP As Non-Secure
Eric Mill <[email protected]> Mon, 8 Feb 2016 23:37:53 -0500
| Newsgroups | gmane.comp.mozilla.security |
|---|---|
| Message-ID | <CANBOYLXSxxrOTUyo7+10so_WSFqut8+7==uYPoniYFRY0grJ8Q@mail.gmail.com> |
On Mon, Feb 8, 2016 at 10:41 PM, Kyle Hamilton <[email protected]> wrote: > > > > The thing that stopped me was "mandatory payments to CAs". This was > another decision by "people who knew better" attempting to enforce a > security policy on those for whom the one-size-fits-all security policy > didn't fit the needs of. I understand this resentment, but I think given widespread inexpensive DV (even before Let's Encrypt), it's not much different than paying a nominal fee to a ICANN-accredited registrar for a domain itself. The $10-12 fees for domains and certs really are pretty nominal, even for folks with no income or lots of debt (which describes me for most of my life). It's a lot different than the $99/year fee you pay for the chance for Apple to approve your app. Those registrars aren't like, morally superior. They have a deal with ICANN, who holds them to non-legally-binding but technically enforceable standards (just like browsers do with CAs), and I'd bet lots of money their operational practices are just as shady underneath the hood as are many CAs. The internet's a messy bunch of messy companies and it does cost money, but we still have a system where you don't have to pay much to play as a domain owner for the basics. And if you don't need "public trust", because *both* parties are informed and able to rely on non-publicly-trusted certificates to communicate in a way they wish, that's always still possible, and nothing Mozilla or Chrome is doing affects that. It's when only one of those parties (the server) is making an informed choice that browsers have a strong opinion. >> Would you write everything on a postcard? or would you at least put > >> the letter in an envelope? > > People choose either/both all the time. > > Yes, but do you ever see a bank sending a statement on a postcard? > I'll add that one major difference here is that ordinary people have the capacity to evaluate the privacy tradeoffs in whether they choose a physical envelope or postcard. They understand the risks a postcard carries, and they can see the metadata that's carried on an envelope either way. People have no concept of the tradeoffs or metadata involved in online communication, which creates a truly corrosive lack of transparency and accountability. Users are treated by various governments and corporations who run invisible services however those governments and corporations wish to treat them, and they can rely on legislative and regulatory bodies to have a very small % of people on staff who personally and completely understand the issues at play. It is fair to describe the use of a physical postcard as an informed choice. No one (of statistical significance) makes an informed choice to use plaintext HTTP as they go about their day. -- Eric > _______________________________________________ > dev-security mailing list > [email protected] > https://lists.mozilla.org/listinfo/dev-security > -- konklone.com | @konklone <https://twitter.com/konklone>