Just Tuesaday, I sent an email around the company discussing SSL vulnerabilities, how they impact our product, and ways we can mitigate that. I've pulled out the parts specific to our product, but the rest may be interesting. I would love feedback on things I may have missed. FWIW, it doesn't instill great confidence in SSL, but it isn't completely horrible. ------------------------ 1. It is possible to pretend to be…
How is Convergence different from the Perspectives add-on[1]? I ask because I honestly don't see any significant advantage to one over the other. [1] https://addons.mozilla.org/en-US/firefox/addon/perspectives/
Should All Web Traffic Be Encrypted?
101–110 of 136 posts
Re: Should All Web Traffic Be Encrypted?
#102Earlier quoted context omitted.
If HTTP referrers never existed, the web would still be huge and would still be full of amazing content. Why should we care about retaining referrers? I think the only reason that people dislike the idea of losing them, is because they've got used to them being there. I don't particularly like the fact that sites which I click through to can see where I'm coming from, or what I was searching for, so I've installed a…
Inertia shouldn't stop us doing something. Where a visitor comes from is very valuable (not just monetarily), and I don't think it really infringes on privacy.
I don't think that referrers should ever have been a part of the protocol and I don't think that the commercial value of them existing should have any influence on whether or not HTTP continues to include them. Unfortunately, both Google and Microsoft benefit financially from the existence of referrer headers, so I don't see them going anywhere in Chrome or IE at least.
Re: Should All Web Traffic Be Encrypted?
#103Wouldn't it provide good additional security if there would be a possibility to define those HTTPS Pins [1] in the DNS, in TXT recods? This would be fairly lightweight way for me to say which CA(s) I use for a particular domain. [1] http://www.imperialviolet.org/2011/05/04/pinning.html
False certificates would be only problem in man-in-the-middle attacks of if the attacker can alter information in dns. In both cases the attacker could also fake the information about valid ca's.
Re: Should All Web Traffic Be Encrypted?
#104One item that this (excellent) blog post does not adress is what to do about referer information which is generally not passed along when clicking on links on sites being browsed over SSL. In order to "get credit" for all of the traffic that they send everywhere twitter had to develop a fairly elaborate system of redirections (built into t.co) to make sure that clicks from twitter.com ended up being sent out to the r…
If HTTP referrers never existed, the web would still be huge and would still be full of amazing content. Why should we care about retaining referrers? I think the only reason that people dislike the idea of losing them, is because they've got used to them being there. I don't particularly like the fact that sites which I click through to can see where I'm coming from, or what I was searching for, so I've installed a…
Re: Should All Web Traffic Be Encrypted?
#105Just Tuesaday, I sent an email around the company discussing SSL vulnerabilities, how they impact our product, and ways we can mitigate that. I've pulled out the parts specific to our product, but the rest may be interesting. I would love feedback on things I may have missed. FWIW, it doesn't instill great confidence in SSL, but it isn't completely horrible. ------------------------ 1. It is possible to pretend to be…
How is Convergence different from the Perspectives add-on[1]? I ask because I honestly don't see any significant advantage to one over the other. [1] https://addons.mozilla.org/en-US/firefox/addon/perspectives/
http://www.youtube.com/watch?v=Z7Wl2FW2TcA (Start from 35m35s)
Re: Should All Web Traffic Be Encrypted?
#106Earlier quoted context omitted.
If HTTP referrers never existed, the web would still be huge and would still be full of amazing content. Why should we care about retaining referrers? I think the only reason that people dislike the idea of losing them, is because they've got used to them being there. I don't particularly like the fact that sites which I click through to can see where I'm coming from, or what I was searching for, so I've installed a…
Referrer information allows website owners to see who is linking to their site. It's like a private, reverse form of tags
If you wanted to see who was linking to your site, and referrer headers didn't exist, you'd use a search engine. Hell, people would build dedicated search engines which alert you when somebody links to your site.
Referrers are good for identifying where a user came from, or what they were searching for when they land on your site. Well, sometimes they don't want you to have that information, and most of the time people are completely unaware that you're getting it.
Re: Should All Web Traffic Be Encrypted?
#107One item that this (excellent) blog post does not adress is what to do about referer information which is generally not passed along when clicking on links on sites being browsed over SSL. In order to "get credit" for all of the traffic that they send everywhere twitter had to develop a fairly elaborate system of redirections (built into t.co) to make sure that clicks from twitter.com ended up being sent out to the r…
If HTTP referrers never existed, the web would still be huge and would still be full of amazing content. Why should we care about retaining referrers? I think the only reason that people dislike the idea of losing them, is because they've got used to them being there. I don't particularly like the fact that sites which I click through to can see where I'm coming from, or what I was searching for, so I've installed a…
While we're at it, let's get rid of User-Agent. No sarcasm intended, I'm serious. It only does bad things.
Re: Should All Web Traffic Be Encrypted?
#108Sorry, off-topic, but as a fan it really bugs me that graphic halfway down appears taken without attribution from Hyperbole and a Half. http://hyperboleandahalf.blogspot.com/
Re: Should All Web Traffic Be Encrypted?
#109Earlier quoted context omitted.
I always expected this to do the same: If it doesn't, then what does it do? Default to http?
That's a relative URL. It would be equivalent to http://static4.scirra.net/static4.scirra.net/images/favicon....