Live data from Hacker News

US Senate website says use HTTP instead of HTTPS

senate.gov

61–70 of 129 posts

Re: US Senate website says use HTTP instead of HTTPS

#61
post #50

Earlier quoted context omitted.

Optimise for the most common case. I imagine there are far more people in the US with broadband connections being put at risk of MITM attacks than people in Kenya with very slow internet trying to look at the US governments website.

I am not against HTTPS per se. Use it for sensitive content.

How do you get around the risk of MITM attacks? It's a sensitive site, given the level of authority it carries for the average user.

Re: US Senate website says use HTTP instead of HTTPS

#62
post #15

I also noticed it seems blocked from access outside the US... so what would happen if a traveling american wants to access it? edit: FYI I'm trying from Kenya. edit2: Using my phone I'm able to switch between wifi, and mobile and on mobile it is unblocked. hmmm Also for those who don't see the Access Denied page but are curious, here is what it reads in full. -------------------- Access Denied You don't have permissi…

It works from Italy.

Re: US Senate website says use HTTP instead of HTTPS

#63
post #15

I also noticed it seems blocked from access outside the US... so what would happen if a traveling american wants to access it? edit: FYI I'm trying from Kenya. edit2: Using my phone I'm able to switch between wifi, and mobile and on mobile it is unblocked. hmmm Also for those who don't see the Access Denied page but are curious, here is what it reads in full. -------------------- Access Denied You don't have permissi…

It's more likely that the server isn't expecting a bunch of techies from hackernews to be hammering it! :)

Re: US Senate website says use HTTP instead of HTTPS

#64
post #23

And it's OK. This "HTTPS everywhere" concept is damaging. I think it should be revised. The amount of overhead and the lack of ability to optimize encrypted content for transferring over, say, satellite or other radio links, is bad. Lots of people still use very expensive (>$2,000 per Mbps) long-RTT connections that would benefit immensely from content optimization techniques. And most of them are cost-sensitive beca…

This is almost as bad as when people were arguing against long signatures on Usenet. https is the least of your worries in terms of overhead.

Frameworks everywhere! :)

Re: US Senate website says use HTTP instead of HTTPS

#65
post #22
post #15

I also noticed it seems blocked from access outside the US... so what would happen if a traveling american wants to access it? edit: FYI I'm trying from Kenya. edit2: Using my phone I'm able to switch between wifi, and mobile and on mobile it is unblocked. hmmm Also for those who don't see the Access Denied page but are curious, here is what it reads in full. -------------------- Access Denied You don't have permissi…

I can see the http version in Japan.

I am in Tokyo and both versions are blocked for me.

Re: US Senate website says use HTTP instead of HTTPS

#66
post #12

Earlier quoted context omitted.

What's weird about them not supporting ipv6?

Well, briefly - the General Service Administration declared "By September 30, 2014, agencies needed to update their public networks to Internet Protocol Version 6 (IPv6)" There is an exception process, but Akamai already supports IPv6 (though they do charge extra for it, booo!). You'd like to think something as high visibility (PR, not web traffic) as senate.gov would comply with the GSA. http://gsablogs.gsa.gov/tech…

The US Senate is not an agency. They are a branch of Congress, and therefore definitely not required to do anything a executive agency tells them to do -- especially if it's reasonable like implementing HTTPS.

Re: US Senate website says use HTTP instead of HTTPS

#67
post #48

How strange, I changed it to http as asked. For me it then asked for my social security number to login and then I needed to confirm some of my banking information for the IRS. I'd expect that to be information you'd want to protect!! I actually double checked to make sure I wasn't on a phising site but I was safe: "senate.gov" why did they need my banking information? Oh well. The above is fiction, but an easy scena…

Also, oh the Senate is telling me I have to install this software to view the website. Well it is the US Senate, so I guess I'll click OK.

It's probably Dianne Feinstein spyware installer. Don't worry, they'll only look at your data for important reasons.

Re: US Senate website says use HTTP instead of HTTPS

#68
post #58

Earlier quoted context omitted.

Commercial mass mail for informing isn't sent in envelopes. I presume that's what the parent was talking about.

It isn't? At least in Germany, commerical mass mail is always sent out in envelopes. I guess that, in this particular case, the reason for the envelopes is to conceal the ads inside them until the recipient has taken the time to open the envelope.

In the USA, most commercial mass advertising mail is in large printed flyer form, not enclosed in any kind of external envelope.

Kinda like this:

http://thumbs.dreamstime.com/z/sale-advertising-papers-15592...

The advertisers pay bulk rates to USPS to stuff all this crap directly in our mailboxes.

There are some exceptions which arrive in envelopes, mostly to trick you into thinking it isn't just spam mail like the rest of the crap.

Re: US Senate website says use HTTP instead of HTTPS

#69
post #15

I also noticed it seems blocked from access outside the US... so what would happen if a traveling american wants to access it? edit: FYI I'm trying from Kenya. edit2: Using my phone I'm able to switch between wifi, and mobile and on mobile it is unblocked. hmmm Also for those who don't see the Access Denied page but are curious, here is what it reads in full. -------------------- Access Denied You don't have permissi…

Portugal, no probs, are you confusing 'blocked' with the stupid message redirecting to http? Which country are you in? now i'm curious? China?!

I can't access it from Portugal

Re: US Senate website says use HTTP instead of HTTPS

#70

Excuse the ignorance, but what's the problem if it's purely an informational read only site? There's no logins, prompts, messaging that can be exploited. What's the problem of it being unencrypted? Don't get me wrong I'm all for https when there's user information to be protected back and forth, I just don't see the applicability for it here.

- Nearly every "informational only" website will end up with feature creep moving it out of that

- Simply not having SSL setup is one thing. But the linked page has, not only a valid SSL certificate, but someone went through the awful process of acquiring an EV certificate. To go through that, and then choose to not use it, boggles the mind

Post reply on HN