Live data from Hacker News

HTTPS on NYTimes.com

open.blogs.nytimes.com

101–110 of 167 posts

Re: HTTPS on NYTimes.com

#101
post #88

Earlier quoted context omitted.

For all newspaper subscriptions (and all other semi-shady companies), I use Privacy.com. It allows you to create silo-ed credit card numbers and specify how much each card is allowed to charge you per week/month/overall. When I want to cancel a newspaper subscription and it's impossibly difficult, I just email them telling them I'd like to cancel the subscription delete the associated credit card. Not my problem anym…

What if they affect your credit record? May be different in the US, but if you did that in the UK and they didn't read your email or whatever, you're likely have them sell the debt to a collection agency which will then place a marker on your credit record. It's then a huge pain in the ass undoing the credit record mark. I still have a default on my record thanks to the cable company here not cancelling our service p…

Yes, they can (and sometimes will, depending on the type of service) keep billing you, and then eventually send you to to collections if you didn't actually cancel your account.

Re: HTTPS on NYTimes.com

#102

Earlier quoted context omitted.

I don't see how anyone can monetize user privacy without NYT's permission, with or without HTTPS. All of the monetization methods, ad trackers on NYT pages, browser fingerprinting, malware on your computer, etc works with or without HTTPS.

Without HTTPS, whoever owns the LAN you use, its ISP, and various intermediary networks can easily track everything that appears in your web browser by reading the same traffic your browser reads.

This is more than a hypothetical concern, too: back in 2011 a number of ISPs came under fire for hijaacking certain search keywords[1], Comcast has injected ads into hotspot traffic[2], and Andreas Gal has alleged that smaller search engines were buying aggregate Google search result data from ISPs trying to improve their result quality[3].

All of that is impossible with HTTPS.

1. https://www.eff.org/deeplinks/2011/07/widespread-search-hija...

2. http://arstechnica.com/tech-policy/2014/09/why-comcasts-java...

3. https://andreasgal.com/2015/03/30/data-is-at-the-heart-of-se...

Re: HTTPS on NYTimes.com

#103
post #102

Earlier quoted context omitted.

Without HTTPS, whoever owns the LAN you use, its ISP, and various intermediary networks can easily track everything that appears in your web browser by reading the same traffic your browser reads.

This is more than a hypothetical concern, too: back in 2011 a number of ISPs came under fire for hijaacking certain search keywords[1], Comcast has injected ads into hotspot traffic[2], and Andreas Gal has alleged that smaller search engines were buying aggregate Google search result data from ISPs trying to improve their result quality[3]. All of that is impossible with HTTPS. 1. https://www.eff.org/deeplinks/2011/0…

Thanks. And even those issues underplay the magnitude of the problem. Look up Deep Packet Inspection, for example. It doesn't take much to read and record the content, and nothing stops them from doing it in the U.S. (AFAIK).

Re: HTTPS on NYTimes.com

#104

Earlier quoted context omitted.

Google Chrome is supposed to soon start flashing a "not secure" warning on HTTP sites that have password forms [0]. That's probably at least one motivation for these publisher moves to HTTPS [0] https://security.googleblog.com/2016/09/moving-towards-more-...

What happens with local LAN machines, like the admin webpage for your wireless access point? It's not like they can go HTTPS?

This is an issue we're encountering. One solution is trust on first use of a self signed cert, which makes the scary untrusted page a one time cost. This isn't terribly easy in the browser though. With more IOT devices entering the market, this could become a more common issue.

Using https for a local network connection will also be more common, in the case you decide you don't trust the network.

Re: HTTPS on NYTimes.com

#105
post #100

No need, who would like to read the Lügenpresse securely anyway. People must be really uninformed to even pay for their own propaganda and then get a Comcast like experience like described below when wanting to cancel. And of course a comodo cert, the worst incompetent thing you can get. https://www.youtube.com/watch?v=pDmj_xe7EIQ . I would prefer Letsencrypt over anything and not at all because its free.

We don't need neo-nazis on HN: http://www.economist.com/news/europe/21710866-1848-1939-hist...

So I am a Neo-Nazi for using a the word Lügenpresse for press the lies and lies over and over again?

And of course you link another fake news article claiming this word has roots on Nazi Germany when in fact this is a lie, its roots are in fact from earlier. But why care and do some actual research when you can just read political correct MSM Lügenpresse?

This guild by association BS does not work on people who can actually think for themselves. Because certain people in history used a word, does not mean everybody who uses it again is also part of this group/believe/mindset/... . But that of course how you political correct people tick. In your minds you create this tainted words nobody should dare to touch ever again because god beware someone evil used them brefore. Your creating a mind prison for yourselves its ridiculous!

Is HN a save space for PCs? I will find out sooner then later I guess.

Re: HTTPS on NYTimes.com

#106

A good step forward. Does the NY Times itself track what its users read? Does it provide that information to others? If so, this change amounts to not protecting user privacy as much as insisting that only the NYT can monetize their users' privacy.

I don't see how anyone can monetize user privacy without NYT's permission, with or without HTTPS. All of the monetization methods, ad trackers on NYT pages, browser fingerprinting, malware on your computer, etc works with or without HTTPS.

Verizon and AT&T (or maybe t-mobile) inject unique headers into http requests over their mobile networks.

Re: HTTPS on NYTimes.com

#107
post #42

Earlier quoted context omitted.

Including the period?

no

Actually, it shouldn't matter. A trailing dot in a hostname signifies a fully-qualified domain name, rather than a relative domain name. Without the dot the router's dns service could technically return 'cbc.ca.some.othersite.net.' as the FQDN.

For those interested, learn more at: http://www.dns-sd.org/trailingdotsindomainnames.html https://en.wikipedia.org/wiki/Fully_qualified_domain_name

Re: HTTPS on NYTimes.com

#108
post #100

Earlier quoted context omitted.

We don't need neo-nazis on HN: http://www.economist.com/news/europe/21710866-1848-1939-hist...

So I am a Neo-Nazi for using a the word Lügenpresse for press the lies and lies over and over again? And of course you link another fake news article claiming this word has roots on Nazi Germany when in fact this is a lie, its roots are in fact from earlier. But why care and do some actual research when you can just read political correct MSM Lügenpresse? This guild by association BS does not work on people who can a…

'Are you a neo-Nazi?' No-one here knows, but you certainly sound like one. The swastika carries a very potent and toxic meaning today that it didn't until the last century or so. If you think symbolism and language are namby pamby liberal constructs with no inherent meaning, I'd encourage you to spray paint one on your house or have one tattooed on your forehead and see if the people you encounter as a result share your disdain for 'political correctness'.

I doubt you are a neo-Nazi. But words have meaning, and while this may just be an abstract game of righteous keyboard warfare to you, perhaps if you have an issue with the objectivity or accuracy of the media it would be best to say that plainly. Code words and innuendo directed at other members of your clique won't convince anyone and may well offend people with a better grasp on history (though that was likely your intention).

Re: HTTPS on NYTimes.com

#109
post #102

Earlier quoted context omitted.

Without HTTPS, whoever owns the LAN you use, its ISP, and various intermediary networks can easily track everything that appears in your web browser by reading the same traffic your browser reads.

This is more than a hypothetical concern, too: back in 2011 a number of ISPs came under fire for hijaacking certain search keywords[1], Comcast has injected ads into hotspot traffic[2], and Andreas Gal has alleged that smaller search engines were buying aggregate Google search result data from ISPs trying to improve their result quality[3]. All of that is impossible with HTTPS. 1. https://www.eff.org/deeplinks/2011/0…

Your mention of how it was 'impossible with HTTPS' to inject ads into web traffic made me recall how, two years ago, Lenovo shipped laptops with software ('Superfish') that injected ads into encrypted webpages:

http://www.theregister.co.uk/2015/02/19/superfish_lenovo_spy...

Lenovo got approximately $250,000 for installing the malware:

http://www.forbes.com/sites/thomasbrewster/2015/02/27/lenovo...

Re: HTTPS on NYTimes.com

#110

The thing the NYT needs to fix (as of earlier last year) is the fact that you can't cancel your subscription without calling them (which is not the case for signing up). I spent 20 minutes[1] on the phone telling them that yes, I really did want to cancel. It was a worse experience than dealing with Comcast, not least because I felt bad for the poor woman who obviously had some financial incentive to get me to stay o…

This is why I only pay for news subscriptions via the App Store (or the Kindle store, if reading a magazine there): I know I can cancel anytime, with a few taps, and without a phone call. And, I know they won't mail me random stuff since all I want is the digital content.

It's the best way right now, and it's silly because the news apps have to eat the Apple Tax just because their own internal policies keep me from signing up through them directly.

Post reply on HN