If you really want to tackle SSL make it less stupid. Self-signed certificates? I want these pinned and treated as secure. I want a notification if they change around the time they expire and a really big warning if they don't. If we must have central trust sources, then have central hash servers so when I visit a new self-signer I can externally verify the hash.
Say the owner of a website with a self-signed cert fears it might have been compromised, and decides to create a new cert. How is the user supposed to distinguish that from a MITM?
Deprecating Non-Secure HTTP
231–240 of 318 posts
Re: Deprecating Non-Secure HTTP
#232Earlier quoted context omitted.
The proposal says: > That would allow things like CSS and other rendering features to still be used by insecure websites ... [but] restrict qualitatively new features, such as access to new hardware capabilities ... [like] persistent permissions for camera and microphone access If accessing my camera over an insecure connection is your definition of doing interesting things, I would be happy to block you. In fact, I…
You changed your opinion quickly. Previously you said: > The plan is to disable some of the "more dangerous" features when the page is requested over HTTP And now you're saying that every new feature falls into this category. Listen, I'm all for going all-in on SSL. What I'm not for is doing until SSL is as seamless and inexpensive as HTTP. What really concerns me is that the https-only nazis do not share this concer…
Also having it developed by 19 university types and one guy from Bell labs was asking for trouble
Re: Deprecating Non-Secure HTTP
#233I should be happy about this -- who wouldn't want the entire web to be encrypted -- but SSL is so broken for normal people. SSL is expensive (wildcard certificates run $70 a year and up), confusing (how does one pick between the 200 different companies selling certificates?), and incredibly difficult to set up (what order should I cat the certificate pieces in again?). If SSL doesn't change, this move will cut the li…
This "certificates are expensive" argument was only valid a decade ago, we have free certs now.
Re: Deprecating Non-Secure HTTP
#234Earlier quoted context omitted.
Why this project: https://letsencrypt.org/ is so important. From the site: Let’s Encrypt is a new Certificate Authority: It’s free, automated, and open. Arriving Mid-2015
You can also get a certificate with as many as 100 domains in the SAN for free from https://buy.wosign.com/free/FreeSSL.html
Re: Deprecating Non-Secure HTTP
#235Earlier quoted context omitted.
1. On a corporate internet, you're probably in a position to deploy your own CA certificates. This is quite common. 2. Let's Encrypt will use an open protocol, so it should be OS-agnostic. 3. "Privileged Contexts" is being developed as a W3C working draft [1]. It's quite likely this won't be just a Mozilla-thing. Google has been fairly aggressive when it comes to pushing for more (and better) SSL as well (see SHA1 ce…
I'm a person who actually deploys .net apps to internal IIS QA servers. If I want them to use HTTPS, I have to configure it. I don't know anything about my own CA certificates. I'm not saying it couldn't happen, but it's certainly easier to suggest just not using firefox if something isn't working.
How does you corporation handle actually important corporate sites that nobody must access?
It sound to my like your corp has some issues on this side.
Re: Deprecating Non-Secure HTTP
#236I should be happy about this -- who wouldn't want the entire web to be encrypted -- but SSL is so broken for normal people. SSL is expensive (wildcard certificates run $70 a year and up), confusing (how does one pick between the 200 different companies selling certificates?), and incredibly difficult to set up (what order should I cat the certificate pieces in again?). If SSL doesn't change, this move will cut the li…
Can someone explain why we can't give SSL certificates along with domain registration? We already trust the DNS, don't we?
Re: Deprecating Non-Secure HTTP
#237Earlier quoted context omitted.
1. On a corporate internet, you're probably in a position to deploy your own CA certificates. This is quite common. 2. Let's Encrypt will use an open protocol, so it should be OS-agnostic. 3. "Privileged Contexts" is being developed as a W3C working draft [1]. It's quite likely this won't be just a Mozilla-thing. Google has been fairly aggressive when it comes to pushing for more (and better) SSL as well (see SHA1 ce…
I'm a person who actually deploys .net apps to internal IIS QA servers. If I want them to use HTTPS, I have to configure it. I don't know anything about my own CA certificates. I'm not saying it couldn't happen, but it's certainly easier to suggest just not using firefox if something isn't working.
Re: Deprecating Non-Secure HTTP
#238I should be happy about this -- who wouldn't want the entire web to be encrypted -- but SSL is so broken for normal people. SSL is expensive (wildcard certificates run $70 a year and up), confusing (how does one pick between the 200 different companies selling certificates?), and incredibly difficult to set up (what order should I cat the certificate pieces in again?). If SSL doesn't change, this move will cut the li…
Well, if cost is your main priority, then startssl.com is the obvious way to go, since it provides free certificates. This "certificates are expensive" argument was only valid a decade ago, we have free certs now.
Re: Deprecating Non-Secure HTTP
#239Earlier quoted context omitted.
No. Consider that DNS request/responses are simple, cleartext UDP packets. There's DNSSEC of course but nobody uses it (and also most security experts don't like it).
That's a bit silly, considering it was developed over a ten year process, and a lot of security professionals had a hand in its design. There are problems with it, which some people are quick to point out, and it is important to be aware of them. The fact that your DNS data is enumerable is an important change, for example. You could compare it to IPsec, which is what most VPNs use, which is comparable in security an…
Re: Deprecating Non-Secure HTTP
#240Earlier quoted context omitted.
Off the top of my head: the bashing of Rob Graham, the defense of concepts that have nothing to do with our rights on the Internet, such as feminism.
I just spent several minutes googling for "EFF" in conjunction with "feminism" and didn't find anything that appeared to be relevant. I did the same for Rob Graham, and he apparently doesn't like the EFF, but I haven't found the EFF saying anything about him yet. I'm sure someone associated with the EFF has mentioned these things at some point, but they don't appear to be major issues. Could you give me some links?
Rob Graham was called out in this article which was subsequently edited: https://twitter.com/ErrataRob/status/553716844650307584
Also, they lie constantly, in lousy attempts of populism and being lavished with attention: http://blog.erratasec.com/2014/07/eff-lies-about-netneutrali...