Live data from Hacker News

Bypassing Browser Security Warnings with Pseudo Password Fields

troyhunt.com

21–30 of 127 posts

Re: Bypassing Browser Security Warnings with Pseudo Password Fields

#21
post #18
post #14

Surely it would be easier to just get a cert. What's preventing these types from doing so?

What's easier for a dev: inserting a few lines of code, or getting access to the production server, setting up letsencrypt (or getting a budget approval for the $10/year certificate)?

Code is rarely the same as "inserting a few lines of code" though. They presumably had to think about how to work around the problem, look for an appropriate font, etc. All for the purpose of hiding a symptom of an underlying problem.

Re: Bypassing Browser Security Warnings with Pseudo Password Fields

#22

If only we had these kinds of strong warnings in the VOIP industry. Nearly every provider barebacks the internet, throwing unencrypted signaling data (phone number dialed, keys pressed during the call, codec to use) and call media over the internet raw, just hoping that no one eavesdrops or alters their data. HIPPA compliance? Nah bruh, unencrypted UDP is just fine! PCI-DSS says we can't take credit cards over this w…

"the HTTPS and IPv6 anti-vaxxer crowd "

What does this mean?

Re: Bypassing Browser Security Warnings with Pseudo Password Fields

#23

"I’ve been speaking with the owner about SSL before I invest in becoming a member, but she’s been told by the dev of the platform (it’s a franchise system called ShopCity.com) that SSL is more about Google’s monopolizing visibility of content, and less to do with security" This is an interesting observation of how Google's technical crusades often align with its profit interests. The main threat that HTTPS everywhere…

Perhaps, but it's fairly easy to un-Google your life nowadays.

Re: Bypassing Browser Security Warnings with Pseudo Password Fields

#24

If only we had these kinds of strong warnings in the VOIP industry. Nearly every provider barebacks the internet, throwing unencrypted signaling data (phone number dialed, keys pressed during the call, codec to use) and call media over the internet raw, just hoping that no one eavesdrops or alters their data. HIPPA compliance? Nah bruh, unencrypted UDP is just fine! PCI-DSS says we can't take credit cards over this w…

"the HTTPS and IPv6 anti-vaxxer crowd " What does this mean?

Pretty sure that means people who refuse to deploy TLS & IPv6, even when their hardware & software stack fully supports it.

Re: Bypassing Browser Security Warnings with Pseudo Password Fields

#26
post #14

Surely it would be easier to just get a cert. What's preventing these types from doing so?

These kind of websites rely on having a huge number of domains (for branding purposes) all doing roughly the same thing. In this case basically 'Shop*.ca'. Of course HTTPS can be automated and facilitated with LetsEncrypt, but it would require switching a working system from one way of doing things to another. It's an investment they are not willing to make, because their customers (shops willing to pay for an extended listing on those websites) are shopkeepers, not tech-savvy users asking for improved security.

Re: Bypassing Browser Security Warnings with Pseudo Password Fields

#28
post #16

Earlier quoted context omitted.

In my experience, the entire world runs on insecure systems (and will continue to do so until companies start getting sued into oblivion for leaking data). Secure systems are the exception--not the norm. It's just not a priority because companies only prioritize things that "add value". So until we attach a real cost to lack-of-security, it won't be valued. I've literally seen a college have admin credentials hosted…

Admins are lazy and busy, hence why UW for example runs a totally insecure PBX, which is surprising considering Avaya is usually one of the better vendors.

Admins lack management support for security issues.

Re: Bypassing Browser Security Warnings with Pseudo Password Fields

#29
LOL, I love the guys filing that bug report with Mozilla... Had to have cost some overtime for their network admins. xD

The way I see it, this - along with most of things - when you place the mechanisms there, people will use them and abuse them.

20 years ago, a browser had 3 MB and today they're 30 and 60 MB large, with much better compression of the installer.

Why do we need this-and-that service integration within the browser, to "follow trends" of the likes of Adobe, Microsoft?..

I don't think so. Cut it all out. Someone wants to watch a video: install a codec. Their service uses different coding? Tough luck, get with the (popular, useful) standard(s), or gtfo.

What the hell do I care about your corporate policy of "creating new jobs" and "advancing development", all you're doing -anyway- is peddling your products. In my browser. On my hardware, which I paid for, meh. Introducing 1000&1 vulnerabilities, where there should be none.

Right, wrong? Know what I mean?

Re: Bypassing Browser Security Warnings with Pseudo Password Fields

#30

If only we had these kinds of strong warnings in the VOIP industry. Nearly every provider barebacks the internet, throwing unencrypted signaling data (phone number dialed, keys pressed during the call, codec to use) and call media over the internet raw, just hoping that no one eavesdrops or alters their data. HIPPA compliance? Nah bruh, unencrypted UDP is just fine! PCI-DSS says we can't take credit cards over this w…

^^ Keys pressed... Jesus Christ, that alone has fueled entire generations of criminals. :))
Post reply on HN