Live data from Hacker News

HTTPS on NYTimes.com

open.blogs.nytimes.com

151–160 of 167 posts

Re: HTTPS on NYTimes.com

#152
post #57

The thing the NYT needs to fix (as of earlier last year) is the fact that you can't cancel your subscription without calling them (which is not the case for signing up). I spent 20 minutes[1] on the phone telling them that yes, I really did want to cancel. It was a worse experience than dealing with Comcast, not least because I felt bad for the poor woman who obviously had some financial incentive to get me to stay o…

Yeah, that's a Comcast-level move, though to be fair, I tried to unsubscribe from The Economist a few years back and it was a nightmare as well [1], so maybe it's just that the news media industry puts all it's eggs in a different basket when it comes to UX. [1] http://www.economist.com/help/manageprintsubscription#cancel...

Huh. I had a trial subscription, found I don't have the time for a daily newspaper plus the Economist, and shot them an email that I wanted to cancel. Received a confirmation the next day.

Re: HTTPS on NYTimes.com

#153

Earlier quoted context omitted.

This isn't an "all or nothing" situation. Enabling HTTPS is a benefit even if it's not perfect. The integrity and authentication it provides are alone a MASSIVE benefit (especially for a news site). Now you'll know that your news is coming from their servers, and nobody else is tampering with it. Then taking into account that it does provide confidentiality, you get rid of "dragnet" style data gathering and inspectio…

"Now you'll know that your news is coming from their servers, and nobody else is tampering with it." I'm a HTTPS noob, can you explain how or why someone would tamper it on normal HTTP? Who would care to target me and what are the chances that NYT has been tampered with ever before?

To take an example that's already happened...

How? By being the user's ISP.

Why? To inject adverts.

What are the chances it affected nytimes.com? Almost certain.

Behold: http://arstechnica.com/tech-policy/2014/09/why-comcasts-java... - and that's not the only case of it.

Re: HTTPS on NYTimes.com

#154

Earlier quoted context omitted.

"Now you'll know that your news is coming from their servers, and nobody else is tampering with it." I'm a HTTPS noob, can you explain how or why someone would tamper it on normal HTTP? Who would care to target me and what are the chances that NYT has been tampered with ever before?

To take an example that's already happened... How? By being the user's ISP. Why? To inject adverts. What are the chances it affected nytimes.com? Almost certain. Behold: http://arstechnica.com/tech-policy/2014/09/why-comcasts-java... - and that's not the only case of it.

And as that last link points out, this isn't a theoretical thing.

Not only do ISPs do it, but wifi hotspots, dodgy wifi routers, malware on anything in-between, and in some (admittedly rare cases) your government.

And the why isn't just ads. But passive tracking (ISPs have been known to analyze your traffic passively and sell that information), active tracking (the famous Verizon super cookie), "page optimization" which frequently breaks sites, and in some cases malware injection into images, executables, or anything else the bad actor could do automatically.

Re: HTTPS on NYTimes.com

#155
post #96

"I'm all in favor of news sites using HTTPS, but I assume they're also going to pad all their articles to a uniform length?" Source: https://twitter.com/matthew_d_green/status/53504312624809574...

That's an interesting point. An eavesdropper would be able to figure out which article you're reading. It might sound silly to worry about this, but you need to be careful in some countries.

This is an interesting puzzle. How much data do you need to add to a page before it becomes impossible (or at least, reasonably difficult) to guess which article someone is reading?

I tried to figure out, but then I remembered that I don't know anything about statistics. Oh well, I had fun: https://github.com/ndbroadbent/nyt_privacy

Re: HTTPS on NYTimes.com

#156

A good step forward. Does the NY Times itself track what its users read? Does it provide that information to others? If so, this change amounts to not protecting user privacy as much as insisting that only the NYT can monetize their users' privacy.

Random coffee shop / hotel / etc wifi owners and other users on the network will only know that you're reading nytimes.com, and not which particular section/article.

It's actually very easy to figure out which article you're reading. I just did a little experiment for fun: https://github.com/ndbroadbent/nyt_privacy

The wifi owners can see that you're reading nytimes.com, but they can also see how much data was transmitted. All they need to do is look up the length of each article, and compare that with how much data the server returned.

Of course, I'm not too worried about hotel owners. I can imagine this technique is already being used by a lot of governments around the world.

Re: HTTPS on NYTimes.com

#157
post #28

They mention it has been a complex undertaking and not complete yet - does anyone know why they can't just sit a traffic manager in front of everything with SSL offloading? Also does anyone know what the new personalisation features are that they mention being able to offer now HTTPS in place?

At any large media organization, there are tremendous amounts of content no longer connected to any CMS that may have hard-coded insecure links/resources in them. Some of them may live on obscure servers or domains. Or the developers/journalists who worked on them and have knowledge of their construction are long gone. These pages are very laborious to find and update. If you don't mind 404ing or breaking a ton of yo…

HTTP URLs redirect to HTTPS, done. That's a basic step of turning on HTTPS

Re: HTTPS on NYTimes.com

#158
post #130

Earlier quoted context omitted.

At any large media organization, there are tremendous amounts of content no longer connected to any CMS that may have hard-coded insecure links/resources in them. Some of them may live on obscure servers or domains. Or the developers/journalists who worked on them and have knowledge of their construction are long gone. These pages are very laborious to find and update. If you don't mind 404ing or breaking a ton of yo…

You also mention "insecure resources", wich I think is a big deal too. I'd imagine there'd be the oddA hard-coded http link to an image that serves an important purpose to an article... that suddenly going missing because a browser refuses to load it would be bad. But I think you hit the nail on the head -- being the "newspaper of record" means you want to ensure that all your content displays like it did the day it…

HTTP URLs redirect to HTTPS

Re: HTTPS on NYTimes.com

#159
post #62

The thing the NYT needs to fix (as of earlier last year) is the fact that you can't cancel your subscription without calling them (which is not the case for signing up). I spent 20 minutes[1] on the phone telling them that yes, I really did want to cancel. It was a worse experience than dealing with Comcast, not least because I felt bad for the poor woman who obviously had some financial incentive to get me to stay o…

Echoes of Comcast ... the NYT is constantly promoting 50% off the posted rates for new subscribers, without ever offering such terms to existing customers. But if you're a "frustrated" long-time customer who's on the verge of canceling, then suddenly the 50% discount is rolled out. In most other industries, loyal customers get better treatment. Or it's the same deal for everyone. These sorts of inverted pricing struc…

In no industry to loyal customers get loss-leader pricing indefinitely.

If you've ever gotten the discount once, you aren't treated worse than new customers.

Re: HTTPS on NYTimes.com

#160
post #69
post #62

Earlier quoted context omitted.

Echoes of Comcast ... the NYT is constantly promoting 50% off the posted rates for new subscribers, without ever offering such terms to existing customers. But if you're a "frustrated" long-time customer who's on the verge of canceling, then suddenly the 50% discount is rolled out. In most other industries, loyal customers get better treatment. Or it's the same deal for everyone. These sorts of inverted pricing struc…

Insurance is another industry with the same inverted pricing structure.

What? Your prices go up every year? I've never seen that.
Post reply on HN