Re: Proposal: Marking HTTP As Non-Secure

Eric Mill <[email protected]> Mon, 8 Feb 2016 23:37:53 -0500
Newsgroups gmane.comp.mozilla.security
Message-ID <CANBOYLXSxxrOTUyo7+10so_WSFqut8+7==uYPoniYFRY0grJ8Q@mail.gmail.com>
On Mon, Feb 8, 2016 at 10:41 PM, Kyle Hamilton <[email protected]> wrote:

>
>
>
> The thing that stopped me was "mandatory payments to CAs".  This was
> another decision by "people who knew better" attempting to enforce a
> security policy on those for whom the one-size-fits-all security policy
> didn't fit the needs of.


I understand this resentment, but I think given widespread inexpensive DV
(even before Let's Encrypt), it's not much different than paying a nominal
fee to a ICANN-accredited registrar for a domain itself. The $10-12 fees
for domains and certs really are pretty nominal, even for folks with no
income or lots of debt (which describes me for most of my life). It's a lot
different than the $99/year fee you pay for the chance for Apple to approve
your app.

Those registrars aren't like, morally superior. They have a deal with
ICANN, who holds them to non-legally-binding but technically enforceable
standards (just like browsers do with CAs), and I'd bet lots of money their
operational practices are just as shady underneath the hood as are many
CAs. The internet's a messy bunch of messy companies and it does cost
money, but we still have a system where you don't have to pay much to play
as a domain owner for the basics.

And if you don't need "public trust", because *both* parties are informed
and able to rely on non-publicly-trusted certificates to communicate in a
way they wish, that's always still possible, and nothing Mozilla or Chrome
is doing affects that. It's when only one of those parties (the server) is
making an informed choice that browsers have a strong opinion.

>> Would you write everything on a postcard? or would you at least put
> >> the letter in an envelope?
> > People choose either/both all the time.
>
> Yes, but do you ever see a bank sending a statement on a postcard?
>

I'll add that one major difference here is that ordinary people have the
capacity to evaluate the privacy tradeoffs in whether they choose a
physical envelope or postcard. They understand the risks a postcard
carries, and they can see the metadata that's carried on an envelope either
way.

People have no concept of the tradeoffs or metadata involved in online
communication, which creates a truly corrosive lack of transparency and
accountability. Users are treated by various governments and corporations
who run invisible services however those governments and corporations wish
to treat them, and they can rely on legislative and regulatory bodies to
have a very small % of people on staff who personally and completely
understand the issues at play.

It is fair to describe the use of a physical postcard as an informed
choice. No one (of statistical significance) makes an informed choice to
use plaintext HTTP as they go about their day.

-- Eric


> _______________________________________________
> dev-security mailing list
> [email protected]
> https://lists.mozilla.org/listinfo/dev-security
>



-- 
konklone.com | @konklone <https://twitter.com/konklone>