And that is the problem.
HTTPS messages need to reform. How about “the website and its data is observable and can be spied on by a third party along the network. Please be careful when entering data.”
321–330 of 525 posts
And that is the problem.
HTTPS messages need to reform. How about “the website and its data is observable and can be spied on by a third party along the network. Please be careful when entering data.”
Earlier quoted context omitted.
The problem is "guaranteed source of truth" doesn't exist. When the network operator is you, or your family/company, you may trust the local DNS to respect your privacy more than you do Cloudflare. Not all names are intended to resolve the same everywhere -- sometimes the local DNS will give the RFC1918 address for a local server instead of the public one, or have a set of local names that are only accessible on the…
If the DNS set by DHCP were only used for local network resources and not internet resources, I wouldn't have a problem with that. That is what it is there for.
I’m surprised at the negative knee-jerk reaction. I actually love this idea immediately. It encapsulates something I kind of already wanted when using HTTPS Everywhere. This doesn’t guarantee the transport is end-to-end secure; I’m sure plenty will strip the encryption at an LB and then possibly send it back over the internet. But, I think it’s a good addition nevertheless. Here’s to hoping for more DoH and encrypted…
DoH changes who gets all your DNS traffic from your ISP and your router to (in practice) a single central DoH provider. Which of those you trust least depends on who you are.
There is nothing about DoH that forces you to use a single company.
Earlier quoted context omitted.
If the DNS set by DHCP were only used for local network resources and not internet resources, I wouldn't have a problem with that. That is what it is there for.
There isn't a bifurcation in the namespace for local resources. Any given name could resolve to a local address or a public one. There isn't even anything requiring a local-only server to have a private address -- it's common to have a public IPv6 address for something which is still only resolvable or accessible from the local network.
Earlier quoted context omitted.
I'm the user and the network operator. Can you give me a comprehensive list of places I need to configure, and notify me when another place software can go around my configuration is added?
I never said there wouldn't be an increased configuration burden for that kind of setup. There was also an increased configuration burden when we moved to widespread HTTPS, but the benefits outweighed the costs.
Are you referring to the whole CA system being an untrustworthy racket?
Earlier quoted context omitted.
I'd be more receptive to this if ISPs weren't snooping on traffic and selling their customer's browsing history. As long as we have to operate under the assumption that every scrap of data we send or request will be picked apart and used against us whenever possible I'd rather encrypt everything and have a little less to worry about.
Perhaps you should get some better laws in your country to prevent this, instead of ruining the web for the rest of the world?
Earlier quoted context omitted.
I think if the user wants that, they should choose to apply it. Not the network operator. Same as how I wouldn't want my network operator inspecting my HTTPS traffic for malware.
I'm not sure why HN won't allow me to reply to ori_b's question below you, however DoH in Firefox (and in Chrome) have clearly spelled out ways to disable it at the network level for those folks who are network operators and want to restrict it due to interference in filtering or split-horizon DNS. https://support.mozilla.org/en-US/kb/configuring-networks-di... Someone previously mentioned Pi-Hole. Pi-Hole provides t…
I still don't really understand this. Yes, it solves that problem, but how is it not also defeating the entire premise? If you had a DNS server from an adversarial network operator, they could just resolve the canary. So it means the browser's DoH is only secure if you can trust your network operator's DNS, at which point, what was its purpose supposed to be?
And the fear is that at some point someone is going to try to "correct" that by removing the check for the canary.
Earlier quoted context omitted.
Using https is making the web a monoculture?
It obviously is. Having just an HTML site now becomes more expensive for no clear reason. Which makes more sense for people to check out Gemini.
On Windows 10, I use Cold Turkey to block distracting websites. I often have issues with Firefox bypassing the blocks on Windows, ignoring the Hosts settings.
On Android, Block Site addons are not compatible with the new Firefox for Android.
I love Firefox, but some recent changes make me feel that I have less control over my browsing experience.
I hope they don't make things 'default' for our 'protection', rather leave some things to the user to decide as per their preferences.
Earlier quoted context omitted.
I never said there wouldn't be an increased configuration burden for that kind of setup. There was also an increased configuration burden when we moved to widespread HTTPS, but the benefits outweighed the costs.
As a user, what is the increased administration burden for http? Are you referring to the whole CA system being an untrustworthy racket?
What is the burden for using HTTPS assuming you DO want to be able to inspect and block HTTPS resources at a network level? Very extensive compared to plain HTTP.