Live data from Hacker News

“Users will only be able to view patents via HTTP. HTTPS will no longer work”

uspto.gov

51–60 of 172 posts

Re: “Users will only be able to view patents via HTTP. HTTPS will no longer work”

#51

The USPTO databases have to be one of the most torturous services to their users in the whole of internet. The UI of both the patent and trademark search is archaic, but not in a HN way but in a really bad way. In patent search, there is no "search" box. Instead, the "quick search" forces you to specify two (and exactly two) text queries on the database columns with obligatory boolean operation.[1] Even if you happen…

Thank goodness for Google patents and patents.justia.com (which is HTTP, by the way). Regardless, much more usable than the Patent Office website.

Re: “Users will only be able to view patents via HTTP. HTTPS will no longer work”

#52
post #45

Earlier quoted context omitted.

Does F5 do any special secret sauce that can't be replicated with an equally powerful set of hardware and a good HAProxy config? I know one of our network admins is continually complaining about how shitty their UI is...

F5 has some secret sauce to it but it's mostly performance related. They have a good chunk of hardware offloading, all the way up to the TLS layer. I seem to remember even the entry license includes full TLS offloading so I doubt the poster above is correct that it is a cost issue. As to if HAProxy can do the job, well, that depends. F5s are complex beasts and they can load balance application specific protocols that…

crypto offloading isn't hard, and can be done on the NIC if you want/need: https://www.nextplatform.com/2016/10/03/server-encryption-fp...

Re: “Users will only be able to view patents via HTTP. HTTPS will no longer work”

#53
it seems like most of the pro https arguments are asserting the right to anonymous public patent inspection. it is fundamentally impossible for the uspto to provide this access* (free speech traps ahead). if you don't want data about access patterns tracked the burden is on the consumer not the provider for public resources

*https://thestack.com/security/2017/04/12/netflix-found-to-le...

Re: “Users will only be able to view patents via HTTP. HTTPS will no longer work”

#55
This is surprising given that the .gov registrar is requiring HTTPS + HSTS for all new agency websites [1], but they specifically exclude existing domains or _renewals_.

I wonder if 18f can help at all, it seems agencies must contact 18f themselves.

1: https://www.digitalgov.gov/2017/04/12/dotgov-domain-registra...

Re: “Users will only be able to view patents via HTTP. HTTPS will no longer work”

#56

This would be interesting for patent research; you could legitimately say "I looked for a patent that already covers X but since you cannot guarantee the data was not modified in transit, I cannot be certain that I saw what was actually in the patents I reviewed".

The law doesn't work like that. Sorry.

Re: “Users will only be able to view patents via HTTP. HTTPS will no longer work”

#57
post #45

Earlier quoted context omitted.

Does F5 do any special secret sauce that can't be replicated with an equally powerful set of hardware and a good HAProxy config? I know one of our network admins is continually complaining about how shitty their UI is...

F5 has some secret sauce to it but it's mostly performance related. They have a good chunk of hardware offloading, all the way up to the TLS layer. I seem to remember even the entry license includes full TLS offloading so I doubt the poster above is correct that it is a cost issue. As to if HAProxy can do the job, well, that depends. F5s are complex beasts and they can load balance application specific protocols that…

SSL offloading is license-limited (TPS-wise) on physical F5 appliances, E.G., `10250v` vs `10200v-SSL`.

Re: “Users will only be able to view patents via HTTP. HTTPS will no longer work”

#58
post #15

Also, at the bottom of the page "This page is owned by Service Desk." What does that mean? And it's legal to publish a .GOV site using Drupal?

Of course it is. What's the alternative? Writing all the websites, and the web servers hosting them, along with the operating systems, with hand-written assembly or something like that?

Re: “Users will only be able to view patents via HTTP. HTTPS will no longer work”

#59
post #29

Fun fact: HSTS https://securityheaders.io/?q=www.uspto.gov&followRedirects=... HSTS is 1 year at the time this comment is posted. They're in for some pain.

That should be considered a non-fun fact :)

They are basically going to be DOSing a huge segment of users who've previously had that header set on their browsers...they're also violating the OMB mandate that requires TLS for all government sites...it is a rather strange move, I can't imagine there is a good reason for it.

EDIT If it is for portal.uspto.gov then HSTS is a non-issue but still a very bad move.

Re: “Users will only be able to view patents via HTTP. HTTPS will no longer work”

#60

Earlier quoted context omitted.

Well if you put on your tinfoil hat - maybe someone wants to track who's viewing which patents, which they can't do when it's encrypted. You're right, it doesn't make any sense to do this, so there must be an ulterior motive.

If that were the case and USPTO were in on the trick, why the need to drop HTTPS? They'd have that data already, so could just share it directly.

Didn't your country just drop the privacy protection rules that hindered ISPs from selling any American's browser history?
Post reply on HN