No https? That's a major concern. It's 2019, (almost) everything needs to be https.
Why? Also there is https on the more sensitive parts of the site (login etc).
Mail a Letter Online
21–30 of 117 posts
Re: Mail a Letter Online
#22This is similar. I've never used it but it looks fun: https://handwriting.io/
this is pretty cool. I would love to see a service takes writing samples in your own handwriting and produces a letter that looks like you wrote it.
That would personally be horrifying to me. Imagine, someone can make it look like you said _anything_.
Re: Mail a Letter Online
#23Too bad there's not a postcard option...
https://lob.com probably has what you're looking for. I've used their service for awhile and it's amazing.
I am very clearly not the intended customer and appreciate that they're willing to take my business anyway.
I also used them for holiday cards two years back, which was
* Fantastic -- super straightforward to write up a small script to call their API and send 1 card to each person on our holiday-card list
* A little weird -- sending 70 holiday cards involved instructing their API to download an identical .pdf holiday card template from a remote server where I hosted that one file 70 times
* Cheap -- they printed and mailed glossy postcards at a very affordable price
* Ever so slightly disappointing -- we got to see maybe 10 of the actual mailed postcards from this run (on family's fridges, in the test copy we sent ourselves, and in the 3 or 4 postcards that we thought were addressed correctly but which were returned to us with an invalid address) and every single one of them had the same printing defect, what looked like a big scuff across a photo. Not sure what the deal was or why it was so consistent on every image. We didn't write in to support because I am pretty sure we are not the target audience.
Great service, A+, huge time saver vs. manually writing so many addresses, still a big fan.
Re: Mail a Letter Online
#24Re: Mail a Letter Online
#25Earlier quoted context omitted.
Why? Also there is https on the more sensitive parts of the site (login etc).
pretty meaningless when you can MITM the page and remove https from all the links
This is one of the silliest arguments that comes up every time "SSL All The Things!" is discussed. The "you" in your story has to be both a Bad Guy and your ISP, and needs to come up with a way to sabotage a site that shows you cat pictures in such a way that it shows malicious cat pictures that somehow do anybody any harm.
So yeah, please MITM this site for us real quick so we can see all the Bad Stuff you're talking about.
Re: Mail a Letter Online
#26This is similar. I've never used it but it looks fun: https://handwriting.io/
this is pretty cool. I would love to see a service takes writing samples in your own handwriting and produces a letter that looks like you wrote it.
Re: Mail a Letter Online
#27Earlier quoted context omitted.
pretty meaningless when you can MITM the page and remove https from all the links
Can you? Please demonstrate. This is one of the silliest arguments that comes up every time "SSL All The Things!" is discussed. The "you" in your story has to be both a Bad Guy and your ISP, and needs to come up with a way to sabotage a site that shows you cat pictures in such a way that it shows malicious cat pictures that somehow do anybody any harm. So yeah, please MITM this site for us real quick so we can see al…
The attitude of "it's cool, only use SSL for the sensitive parts" hasn't been true for a decade.
Re: Mail a Letter Online
#28Earlier quoted context omitted.
Can you? Please demonstrate. This is one of the silliest arguments that comes up every time "SSL All The Things!" is discussed. The "you" in your story has to be both a Bad Guy and your ISP, and needs to come up with a way to sabotage a site that shows you cat pictures in such a way that it shows malicious cat pictures that somehow do anybody any harm. So yeah, please MITM this site for us real quick so we can see al…
https://moxie.org/software/sslstrip/ The attitude of "it's cool, only use SSL for the sensitive parts" hasn't been true for a decade.
I don't disagree that it is possible to mess with http traffic in flight if it's not encrypted. I do disagree that a) there are bad guys between me and the http://catpictures.com right now and b) They have targeted me with malicious cat pictures that will cause damage somehow.
My sites that allow logins are all https only. My "cat picture" site is not. Because it doesn't need https.
Re: Mail a Letter Online
#29Earlier quoted context omitted.
https://moxie.org/software/sslstrip/ The attitude of "it's cool, only use SSL for the sensitive parts" hasn't been true for a decade.
Again, that looks like it needs to be sitting somewhere between the end user and the webserver. I don't disagree that it is possible to mess with http traffic in flight if it's not encrypted. I do disagree that a) there are bad guys between me and the http://catpictures.com right now and b) They have targeted me with malicious cat pictures that will cause damage somehow. My sites that allow logins are all https only.…
And yes, the point of MITM is that there has to be a malicious actor in the middle. This is mainly a threat when using public WiFi, like at an airport or a coffee shop. It's absolutely trivial for some bored individual to run SSLstrip for funsies and distribute malware through any HTTP connections.
Also, an attacker doesn't need to somehow create malware-infested versions of the cat pictures on your site. They only need to append some javascript at the end of your site's body tag, which again, is trivial for a script to do. And maybe a transparent image with the malicious payload should they have JS disabled.
To those wondering how they might protect themselves from these sorts of attacks when using non-SSL sites on public WiFi, this is where a VPN comes in handy. All of your connections will be encrypted and no longer vulnerable to MITM attacks.
Re: Mail a Letter Online
#30This makes it look like there are some unresolved challenges with fulfillment: https://www.bbb.org/us/wa/seattle/profile/international-mail...
The biggest annoyance is the horrible UX for entering recipient's address. I'd like to type the two lines on the envelope. Instead, I need to go through this form adding them as a contact, with fields for e.g. city and state. Most of my letters are one-offs, and it's a bunch of cut-and-paste work. Still beats doing my own mailing, though.