Excuse the ignorance, but what's the problem if it's purely an informational read only site? There's no logins, prompts, messaging that can be exploited. What's the problem of it being unencrypted? Don't get me wrong I'm all for https when there's user information to be protected back and forth, I just don't see the applicability for it here.
US Senate website says use HTTP instead of HTTPS
31–40 of 129 posts
Re: US Senate website says use HTTP instead of HTTPS
#32Excuse the ignorance, but what's the problem if it's purely an informational read only site? There's no logins, prompts, messaging that can be exploited. What's the problem of it being unencrypted? Don't get me wrong I'm all for https when there's user information to be protected back and forth, I just don't see the applicability for it here.
1. MITM to return fraudulent data ("click here to input your personal data to collect your government cheque from this new federal grant!")
2. Recording browsing activity ("gee Mr. Smith, you sure do spend a lot of time looking up laws about X. Seems like a good thing to blackmail you about")
Working those into actual problems is an exercise for the reader, but they're mostly what https is for
There is also the benefit that HTTPS is harder to mass-surveil, and harder for your ISP to play shenanigans like injecting their adverts and tracking headers into the page (https://www.eff.org/deeplinks/2014/11/verizon-x-uidh)
Re: US Senate website says use HTTP instead of HTTPS
#33Re: US Senate website says use HTTP instead of HTTPS
#34I also noticed it seems blocked from access outside the US... so what would happen if a traveling american wants to access it? edit: FYI I'm trying from Kenya. edit2: Using my phone I'm able to switch between wifi, and mobile and on mobile it is unblocked. hmmm Also for those who don't see the Access Denied page but are curious, here is what it reads in full. -------------------- Access Denied You don't have permissi…
Which country are you in? now i'm curious? China?!
Re: US Senate website says use HTTP instead of HTTPS
#35I also noticed it seems blocked from access outside the US... so what would happen if a traveling american wants to access it? edit: FYI I'm trying from Kenya. edit2: Using my phone I'm able to switch between wifi, and mobile and on mobile it is unblocked. hmmm Also for those who don't see the Access Denied page but are curious, here is what it reads in full. -------------------- Access Denied You don't have permissi…
Portugal, no probs, are you confusing 'blocked' with the stupid message redirecting to http? Which country are you in? now i'm curious? China?!
and also I accessed the site from the US (tunnel ;-) and it was unblocked, and then I saw the redirect to http.
Re: US Senate website says use HTTP instead of HTTPS
#36Earlier quoted context omitted.
Portugal, no probs, are you confusing 'blocked' with the stupid message redirecting to http? Which country are you in? now i'm curious? China?!
nope, "ACCESS DENIED" and also I accessed the site from the US (tunnel ;-) and it was unblocked, and then I saw the redirect to http.
Re: US Senate website says use HTTP instead of HTTPS
#37Re: US Senate website says use HTTP instead of HTTPS
#38Re: US Senate website says use HTTP instead of HTTPS
#39And it's OK. This "HTTPS everywhere" concept is damaging. I think it should be revised. The amount of overhead and the lack of ability to optimize encrypted content for transferring over, say, satellite or other radio links, is bad. Lots of people still use very expensive (>$2,000 per Mbps) long-RTT connections that would benefit immensely from content optimization techniques. And most of them are cost-sensitive beca…
You mean that super costly 1KB in front of a request that pulls extra megabyte of data on a typical website? I really hope you missed a /s
Re: US Senate website says use HTTP instead of HTTPS
#40Earlier quoted context omitted.
At a guess, it was built years ago by an agency selected on the basis of anything other than technical competence. As a result it probably has thousands of hard coded HTTP links and an oddly configured out of date web server. Given the 'encryption is only used by terrorists' climate, spending the time and money to make it work for https sounds like a hard sell. No sources, but I have done some work in UK public secto…
Well it does the job, and if it aint broken why fix it?