Live data from Hacker News

HTTPS on Your Landing Page Is Important

troyhunt.com

101–110 of 307 posts

Re: HTTPS on Your Landing Page Is Important

#101
post #94

Earlier quoted context omitted.

At that point, will we start seeing attackers targeting DNS instead?

You need to get to global DNS to get a valid cert. When certificate transparency logs become mandatory, that case will be detectable though not preventable.

Surely good enough detection is just one step from prevention? Detect fraudulent cert, revoke it. Or have I missed a layer?

Re: HTTPS on Your Landing Page Is Important

#103

Probably not a good person to piss off. Several months ago I recall a website owner posted a bug to Firefox saying he didn’t need HTTPs and that Firefox shouldn’t tell users it’s insecure. Within hours his database was pwned.

And it's so easy for anyone nowadays to get SSL with Let's Encrypt... I remember a few years ago when there was no way you could do it for side projects because certs were 100/yr., now they're free.

It is not easy if you are on a shared domain and it is not supported by your host. Please don't run around saying it is easy for everyone.

Re: HTTPS on Your Landing Page Is Important

#104
post #65

About 8 years ago Natwest had a policy of having a "browser whitelist" which was rarely updated. Each time a security update for chrome or firefox came out it would be 2 weeks before online banking was accessible, and using any pre-release versions were out of the question. I complained and a member of the dev team phoned me up and after a long discussion about why this was madness he told me that it was better to us…

For some dumb reason the Bank of America website is ok with firefox on windows, but throws up a big red error message when you try to use firefox on mac.

https://www.bankofamerica.com/information/supported-browsers...

Re: HTTPS on Your Landing Page Is Important

#105

Earlier quoted context omitted.

Why is it you (or someone there) chose "Secure" in the address bar rather than something like "Private"? It seems like the people who don't understand what httpS means at all see "Secure" and think "oh this site is safe/secure" no matter what this site is, like if it's a phishing site. I'm not one to be very pedantic, but "Secure" up there really doesn't mean "Secure" at all. I know what it means, but people falling…

This is bikeshedding. The only users who would be able to distinguish the meaning of "secure" and "private" in their address bar are people who already understand what https is and isn't.

This was an honest question, really. I didn't say I had the right answer, I was wondering why they chose "Secure"

Re: HTTPS on Your Landing Page Is Important

#106

Earlier quoted context omitted.

Don't think about _you_, think about the layman. Who probably has a WiFi router from 5 years ago with outdated firmware that their ISP can't be bothered patching.

The layman clicks on links that say "you have a virus; download this tool to remove it". They then click 'Yes I authorize' to verify that the downloaded program should be allowed to corrupt their machine. I fail to see how the bank changing their website to HTTPS is going to save the average Joe. There are so many websites and things that operate over HTTP that make our machines vulnerable, that I think it is foolish…

This sounds a lot like "we can't protect average joes from themselves, so let's not bother adding protections"? Sure there are always other attack vectors, but that doesn't excuse ignoring the ones that are easy to fix.

Re: HTTPS on Your Landing Page Is Important

#107
post #89
post #83

Earlier quoted context omitted.

How about all it really means? "Encrypted"

HTTPS means more than just encryption. There is also authentication and integrity guarantees in SSL.

But the extras beyond encryption are definately not guarantees. [1] HTTPS means encrypted HTTP. Everything else is "I trust the certificate authority to provide oversight and verification." It may just be me, but I don't trust the fine, upstanding CAs we have now-a-days. 1: https://stripe.ian.sh/

Re: HTTPS on Your Landing Page Is Important

#108

Earlier quoted context omitted.

Why is it you (or someone there) chose "Secure" in the address bar rather than something like "Private"? It seems like the people who don't understand what httpS means at all see "Secure" and think "oh this site is safe/secure" no matter what this site is, like if it's a phishing site. I'm not one to be very pedantic, but "Secure" up there really doesn't mean "Secure" at all. I know what it means, but people falling…

Couldn't "private" also not mean "private"? For instance: when you're on Facebook, couldn't people think they are exchanging private messages because the address bar says "private"? "secure" means "secure connection" to me, and it sounds perfectly appropriate. Maybe you can't find a better term for "secure" because it's perfectly fine, already..?

> Maybe you can't find a better term for "secure" because it's perfectly fine, already..?

Could be! Someone else suggested "Encrypted", seems like a good word. I really don't know.

Re: HTTPS on Your Landing Page Is Important

#109
post #78

Earlier quoted context omitted.

I was looking up details of the new Microsoft Surface recently, so hit the top link in a google search which was (supposedly) on Microsoft.com It wouldn’t load because Facebook.com was blocked and apparently they were doing a full redirect via fb. Crazy.

This may in fact be because Google lets advertisers set a totally different URL than the one that they actually direct you to, so that advertisers can implement various tracking schemes. This is also exploited by malicious actors to occasionally buy out fake ads for amazon.com or bestbuy.com (or even, hilariously, youtube.com) which actually direct you to support scam websites claiming your computer is infected. Goog…

[deleted]

Re: HTTPS on Your Landing Page Is Important

#110
post #98
post #78

Earlier quoted context omitted.

I was looking up details of the new Microsoft Surface recently, so hit the top link in a google search which was (supposedly) on Microsoft.com It wouldn’t load because Facebook.com was blocked and apparently they were doing a full redirect via fb. Crazy.

You didn't click on a search result, you clicked on an advertisement.

A good reason to use at the very least adblock.
Post reply on HN