Live data from Hacker News

Deprecating Non-Secure HTTP

blog.mozilla.org

231–240 of 318 posts

Re: Deprecating Non-Secure HTTP

#231
post #107

If you really want to tackle SSL make it less stupid. Self-signed certificates? I want these pinned and treated as secure. I want a notification if they change around the time they expire and a really big warning if they don't. If we must have central trust sources, then have central hash servers so when I visit a new self-signer I can externally verify the hash.

Say the owner of a website with a self-signed cert fears it might have been compromised, and decides to create a new cert. How is the user supposed to distinguish that from a MITM?

That's what the central hash servers are for. Am I being MITM'd? Well, ignoring a global adversary, the problem is usually local. But CA's don't solve the global problem either.

Re: Deprecating Non-Secure HTTP

#232
post #165
post #162

Earlier quoted context omitted.

The proposal says: > That would allow things like CSS and other rendering features to still be used by insecure websites ... [but] restrict qualitatively new features, such as access to new hardware capabilities ... [like] persistent permissions for camera and microphone access If accessing my camera over an insecure connection is your definition of doing interesting things, I would be happy to block you. In fact, I…

You changed your opinion quickly. Previously you said: > The plan is to disable some of the "more dangerous" features when the page is requested over HTTP And now you're saying that every new feature falls into this category. Listen, I'm all for going all-in on SSL. What I'm not for is doing until SSL is as seamless and inexpensive as HTTP. What really concerns me is that the https-only nazis do not share this concer…

Its a bit like the ipv6 band wagon 20 years ago I or anyone with a trivial knowledge of the internet/networking, could have pointed out that developing a new standard with NO thought to inter operation would not work.

Also having it developed by 19 university types and one guy from Bell labs was asking for trouble

Re: Deprecating Non-Secure HTTP

#233

I should be happy about this -- who wouldn't want the entire web to be encrypted -- but SSL is so broken for normal people. SSL is expensive (wildcard certificates run $70 a year and up), confusing (how does one pick between the 200 different companies selling certificates?), and incredibly difficult to set up (what order should I cat the certificate pieces in again?). If SSL doesn't change, this move will cut the li…

Well, if cost is your main priority, then startssl.com is the obvious way to go, since it provides free certificates.

This "certificates are expensive" argument was only valid a decade ago, we have free certs now.

Re: Deprecating Non-Secure HTTP

#234
post #24

Earlier quoted context omitted.

Why this project: https://letsencrypt.org/ is so important. From the site: Let’s Encrypt is a new Certificate Authority: It’s free, automated, and open. Arriving Mid-2015

You can also get a certificate with as many as 100 domains in the SAN for free from https://buy.wosign.com/free/FreeSSL.html

That site forwards me to a 407 error in chinese. Dead end for me.

Re: Deprecating Non-Secure HTTP

#235
post #130

Earlier quoted context omitted.

1. On a corporate internet, you're probably in a position to deploy your own CA certificates. This is quite common. 2. Let's Encrypt will use an open protocol, so it should be OS-agnostic. 3. "Privileged Contexts" is being developed as a W3C working draft [1]. It's quite likely this won't be just a Mozilla-thing. Google has been fairly aggressive when it comes to pushing for more (and better) SSL as well (see SHA1 ce…

I'm a person who actually deploys .net apps to internal IIS QA servers. If I want them to use HTTPS, I have to configure it. I don't know anything about my own CA certificates. I'm not saying it couldn't happen, but it's certainly easier to suggest just not using firefox if something isn't working.

So you handle deployment of apps inside a corporate network, and have no idea on how to manage you own CA?

How does you corporation handle actually important corporate sites that nobody must access?

It sound to my like your corp has some issues on this side.

Re: Deprecating Non-Secure HTTP

#236

I should be happy about this -- who wouldn't want the entire web to be encrypted -- but SSL is so broken for normal people. SSL is expensive (wildcard certificates run $70 a year and up), confusing (how does one pick between the 200 different companies selling certificates?), and incredibly difficult to set up (what order should I cat the certificate pieces in again?). If SSL doesn't change, this move will cut the li…

Can someone explain why we can't give SSL certificates along with domain registration? We already trust the DNS, don't we?

A certificate given by the domain registrar makes a lot of sense to me. My registrar holds my data and indeed can certify the identity of the domain.

Re: Deprecating Non-Secure HTTP

#237
post #130

Earlier quoted context omitted.

1. On a corporate internet, you're probably in a position to deploy your own CA certificates. This is quite common. 2. Let's Encrypt will use an open protocol, so it should be OS-agnostic. 3. "Privileged Contexts" is being developed as a W3C working draft [1]. It's quite likely this won't be just a Mozilla-thing. Google has been fairly aggressive when it comes to pushing for more (and better) SSL as well (see SHA1 ce…

I'm a person who actually deploys .net apps to internal IIS QA servers. If I want them to use HTTPS, I have to configure it. I don't know anything about my own CA certificates. I'm not saying it couldn't happen, but it's certainly easier to suggest just not using firefox if something isn't working.

The other option is you can just install your self signed certs onto the client PCs via group policies.

Re: Deprecating Non-Secure HTTP

#238

I should be happy about this -- who wouldn't want the entire web to be encrypted -- but SSL is so broken for normal people. SSL is expensive (wildcard certificates run $70 a year and up), confusing (how does one pick between the 200 different companies selling certificates?), and incredibly difficult to set up (what order should I cat the certificate pieces in again?). If SSL doesn't change, this move will cut the li…

Well, if cost is your main priority, then startssl.com is the obvious way to go, since it provides free certificates. This "certificates are expensive" argument was only valid a decade ago, we have free certs now.

Free as long as you never have to revoke them. Which means people primarily looking at costs are actually incentived to not revoke compromised certs.

Re: Deprecating Non-Secure HTTP

#239

Earlier quoted context omitted.

No. Consider that DNS request/responses are simple, cleartext UDP packets. There's DNSSEC of course but nobody uses it (and also most security experts don't like it).

That's a bit silly, considering it was developed over a ten year process, and a lot of security professionals had a hand in its design. There are problems with it, which some people are quick to point out, and it is important to be aware of them. The fact that your DNS data is enumerable is an important change, for example. You could compare it to IPsec, which is what most VPNs use, which is comparable in security an…

If experts take 10 years to make a product that sucks, the product still sucks.

Re: Deprecating Non-Secure HTTP

#240

Earlier quoted context omitted.

Off the top of my head: the bashing of Rob Graham, the defense of concepts that have nothing to do with our rights on the Internet, such as feminism.

I just spent several minutes googling for "EFF" in conjunction with "feminism" and didn't find anything that appeared to be relevant. I did the same for Rob Graham, and he apparently doesn't like the EFF, but I haven't found the EFF saying anything about him yet. I'm sure someone associated with the EFF has mentioned these things at some point, but they don't appear to be major issues. Could you give me some links?

Feminism: most of their staff are feminists. I'm not going to spend my time googling and posting links. Here's a start https://www.eff.org/about/staff

Rob Graham was called out in this article which was subsequently edited: https://twitter.com/ErrataRob/status/553716844650307584

Also, they lie constantly, in lousy attempts of populism and being lavished with attention: http://blog.erratasec.com/2014/07/eff-lies-about-netneutrali...

Post reply on HN