HTTPS on NYTimes.com
151–160 of 167 posts
Re: HTTPS on NYTimes.com
#152The thing the NYT needs to fix (as of earlier last year) is the fact that you can't cancel your subscription without calling them (which is not the case for signing up). I spent 20 minutes[1] on the phone telling them that yes, I really did want to cancel. It was a worse experience than dealing with Comcast, not least because I felt bad for the poor woman who obviously had some financial incentive to get me to stay o…
Yeah, that's a Comcast-level move, though to be fair, I tried to unsubscribe from The Economist a few years back and it was a nightmare as well [1], so maybe it's just that the news media industry puts all it's eggs in a different basket when it comes to UX. [1] http://www.economist.com/help/manageprintsubscription#cancel...
Re: HTTPS on NYTimes.com
#153Earlier quoted context omitted.
This isn't an "all or nothing" situation. Enabling HTTPS is a benefit even if it's not perfect. The integrity and authentication it provides are alone a MASSIVE benefit (especially for a news site). Now you'll know that your news is coming from their servers, and nobody else is tampering with it. Then taking into account that it does provide confidentiality, you get rid of "dragnet" style data gathering and inspectio…
"Now you'll know that your news is coming from their servers, and nobody else is tampering with it." I'm a HTTPS noob, can you explain how or why someone would tamper it on normal HTTP? Who would care to target me and what are the chances that NYT has been tampered with ever before?
How? By being the user's ISP.
Why? To inject adverts.
What are the chances it affected nytimes.com? Almost certain.
Behold: http://arstechnica.com/tech-policy/2014/09/why-comcasts-java... - and that's not the only case of it.
Re: HTTPS on NYTimes.com
#154Earlier quoted context omitted.
"Now you'll know that your news is coming from their servers, and nobody else is tampering with it." I'm a HTTPS noob, can you explain how or why someone would tamper it on normal HTTP? Who would care to target me and what are the chances that NYT has been tampered with ever before?
To take an example that's already happened... How? By being the user's ISP. Why? To inject adverts. What are the chances it affected nytimes.com? Almost certain. Behold: http://arstechnica.com/tech-policy/2014/09/why-comcasts-java... - and that's not the only case of it.
Not only do ISPs do it, but wifi hotspots, dodgy wifi routers, malware on anything in-between, and in some (admittedly rare cases) your government.
And the why isn't just ads. But passive tracking (ISPs have been known to analyze your traffic passively and sell that information), active tracking (the famous Verizon super cookie), "page optimization" which frequently breaks sites, and in some cases malware injection into images, executables, or anything else the bad actor could do automatically.
Re: HTTPS on NYTimes.com
#155"I'm all in favor of news sites using HTTPS, but I assume they're also going to pad all their articles to a uniform length?" Source: https://twitter.com/matthew_d_green/status/53504312624809574...
This is an interesting puzzle. How much data do you need to add to a page before it becomes impossible (or at least, reasonably difficult) to guess which article someone is reading?
I tried to figure out, but then I remembered that I don't know anything about statistics. Oh well, I had fun: https://github.com/ndbroadbent/nyt_privacy
Re: HTTPS on NYTimes.com
#156A good step forward. Does the NY Times itself track what its users read? Does it provide that information to others? If so, this change amounts to not protecting user privacy as much as insisting that only the NYT can monetize their users' privacy.
Random coffee shop / hotel / etc wifi owners and other users on the network will only know that you're reading nytimes.com, and not which particular section/article.
The wifi owners can see that you're reading nytimes.com, but they can also see how much data was transmitted. All they need to do is look up the length of each article, and compare that with how much data the server returned.
Of course, I'm not too worried about hotel owners. I can imagine this technique is already being used by a lot of governments around the world.
Re: HTTPS on NYTimes.com
#157They mention it has been a complex undertaking and not complete yet - does anyone know why they can't just sit a traffic manager in front of everything with SSL offloading? Also does anyone know what the new personalisation features are that they mention being able to offer now HTTPS in place?
At any large media organization, there are tremendous amounts of content no longer connected to any CMS that may have hard-coded insecure links/resources in them. Some of them may live on obscure servers or domains. Or the developers/journalists who worked on them and have knowledge of their construction are long gone. These pages are very laborious to find and update. If you don't mind 404ing or breaking a ton of yo…
Re: HTTPS on NYTimes.com
#158Earlier quoted context omitted.
At any large media organization, there are tremendous amounts of content no longer connected to any CMS that may have hard-coded insecure links/resources in them. Some of them may live on obscure servers or domains. Or the developers/journalists who worked on them and have knowledge of their construction are long gone. These pages are very laborious to find and update. If you don't mind 404ing or breaking a ton of yo…
You also mention "insecure resources", wich I think is a big deal too. I'd imagine there'd be the oddA hard-coded http link to an image that serves an important purpose to an article... that suddenly going missing because a browser refuses to load it would be bad. But I think you hit the nail on the head -- being the "newspaper of record" means you want to ensure that all your content displays like it did the day it…
Re: HTTPS on NYTimes.com
#159The thing the NYT needs to fix (as of earlier last year) is the fact that you can't cancel your subscription without calling them (which is not the case for signing up). I spent 20 minutes[1] on the phone telling them that yes, I really did want to cancel. It was a worse experience than dealing with Comcast, not least because I felt bad for the poor woman who obviously had some financial incentive to get me to stay o…
Echoes of Comcast ... the NYT is constantly promoting 50% off the posted rates for new subscribers, without ever offering such terms to existing customers. But if you're a "frustrated" long-time customer who's on the verge of canceling, then suddenly the 50% discount is rolled out. In most other industries, loyal customers get better treatment. Or it's the same deal for everyone. These sorts of inverted pricing struc…
If you've ever gotten the discount once, you aren't treated worse than new customers.
Re: HTTPS on NYTimes.com
#160Earlier quoted context omitted.
Echoes of Comcast ... the NYT is constantly promoting 50% off the posted rates for new subscribers, without ever offering such terms to existing customers. But if you're a "frustrated" long-time customer who's on the verge of canceling, then suddenly the 50% discount is rolled out. In most other industries, loyal customers get better treatment. Or it's the same deal for everyone. These sorts of inverted pricing struc…
Insurance is another industry with the same inverted pricing structure.