Live data from Hacker News

Google Will Soon Shame All Websites That Are Unencrypted

motherboard.vice.com

151–160 of 369 posts

Re: Google Will Soon Shame All Websites That Are Unencrypted

#151

Should static content be encrypted over https? I think it's fair for chrome to call out with an x as I've literally seen local lunch joints take orders with credit card info over http but to serve mostly static pages like the new yorker over http only means that the user's privacy is compromised in that people can see what you're reading - does that warrant down ranking searches? I'm just curious - I work mostly on p…

Because mobile carriers are given broad discretion to do whatever they want to do to your traffic.

They cheerfully modify content, and have built infrastructure to do it even more.

Re: Google Will Soon Shame All Websites That Are Unencrypted

#152
post #32

Earlier quoted context omitted.

Isn't that what Let's Encrypt is aiming for? Install a package, which configures a cronjob for you? https://letsencrypt.org/howitworks/ Which could just even become a default but optional dependency of your distro's web server package, or part of your Docker container, or whatever.

Ok I'm new to this and I know it's still beta, but it seems: 1. Still WAY too complicated (look at all the stuff you have to know and type) 2. Doesn't seem to support my preferred OS (Windows) or web server (IIS) what-so-ever. Which is strange since, from my experience, installing certs in IIS is already far easier than in Apache and Nginx. (Although maybe that's why they perceive it as less of a priority?)

Hi, I think the IIS support effort that's furthest along is described at https://community.letsencrypt.org/t/how-letsencrypt-work-for... ; maybe that will be useful for you if you want to try Let's Encrypt on your IIS system.

We've had hundreds of people remark that they found Let's Encrypt faster and easier to use than other CA offerings (though most of those people were using Apache on Debian-based systems), so I think we are getting somewhere. But we definitely hope that upstream web server projects and hosting environments will integrate ACME clients of their own, like Caddy has done, so that eventually most people won't need to run an external client at all and won't have to worry about compatibility or integration problems.

Re: Google Will Soon Shame All Websites That Are Unencrypted

#153

Earlier quoted context omitted.

No. Obviously less is wrong. Here is an example: login over HTTP deliberate because the site doesn't support HTTPS is definitely not less sensitive.

Of course, but there's a general expectation that stuff served over HTTP isn't sensitive. Breaking HTTPS where it's deliberately used is something that certainly deserves a warning.

That's true, but I think at some point HTTP should go away. The deprecation should happen. I think we need to get to state where HTTPS is HTTP and there is no "HTTPS" at all. Everyone can easily get a free certificate, and for commercial they can spend hundreds if they want to "prove" more. Like I said in another comment, I don't see a problem with sharing cat photos over HTTP. But if possible, https is definitely not going to hurt. But given most sites are HTTP, yes, probably going to hurt ranking. Old websites running on old CMS won't be able upgrade much. Simiarily, no one should be running FTP. It should SFTP, but setting up SFTP is pain in the ass with chroot and all that. Technology really need to made simpler. Speaking from an ops standpoint.

Re: Google Will Soon Shame All Websites That Are Unencrypted

#154
post #104
post #23

Why do we have to go through this whole SSL certificates thing and can't just have a simple, automatically secure, I-do-nothing-and-my-website-is-secure protocol? Seriously though. If secure is the default from now on, why can't it actually be the default?

Seriously this. I don't see why encryption and website verification have been wrapped up in the same thing (SSL certs). They're two different things. Encryption should be free, automatic and default.

If you don't have a way to confirm that the key you're seeing from the other site is right, you're inherently vulnerable to a man-in-the-middle attack which removes the benefits of the encryption against the attacker.

https://en.wikipedia.org/wiki/Man-in-the-middle_attack

httpS://en.wikipedia.org/wiki/Zooko's_triangle

It's not clear that the certificate authority system was or is the best solution to this problem, but it is a problem that calls for some solution. In the case of Domain Validation, we only try to confirm that the key is appropriate to use with the domain name, which is the smallest possible kind of confirmation that can be done to address the crypto problem. There's no attempt to validate or verify anything else about the site.

Re: Google Will Soon Shame All Websites That Are Unencrypted

#155
post #131

Earlier quoted context omitted.

This is an awkward argument. One of my sites documents how to configure servers, for example. What excuse is there that something like that needs to be encrypted? The most legitimate reason I've heard is for privacy. I don't believe the gov't is going to lock someone up for learning how to serve web pages.

Integrity protection. There are a lot of ways to instruct someone to configure their web server in a way that is subtly insecure, not to mention attacks like http://thejh.net/misc/website-terminal-copy-paste It'd be slightly nice if we were able to have integrity-protected HTTP without encryption (lower overhead, easier debugging with packet dumps), but the advantages are minimal (ciphers are not really the overhead,…

You can already send unecrypted authenticated data with HTTPS.

Re: Google Will Soon Shame All Websites That Are Unencrypted

#156
Consider this:

- Squarespace doesn't support SSL (other than on their ecommerce checkout pages) [1]

- Weebly only allows it on their $25/mo business plan [2]

- Wordpress.com doesn't support SSL for sites with custom domains [3]

- If you've never experienced the process of requesting, purchasing, and then installing an SSL certificate using a hosting control panel like Plesk or cPanel, let me tell you–it's a nightmare.

All that to say, this is an interesting development that will leave a large % of small business websites with a red mark in their browser.

[1] https://support.squarespace.com/hc/en-us/articles/205815898-...

[2] http://www.weebly.com/pricing

[3] https://en.forums.wordpress.com/topic/support-for-https-for-...

Re: Google Will Soon Shame All Websites That Are Unencrypted

#157

Yes, shame all libraries/swimming pools giving their schedule online without HTTPS. Shame gutenberg project, the documentations for OS, code, your washing machine. Why would money from libraries gutenberg project, NGOs informations go to more expansive OPEX for web hosting when an information is clearly designed and OK to be public? And does not require adds or payment. Google has some godwin point very authoritative…

> Yes, shame all libraries/swimming pools giving their schedule online without HTTPS. Shame gutenberg project, the documentations for OS, code, your washing machine. So it's OK for someone to tamper with your documentation to trick you into doing something dangerous? Is it OK for a librarian to give out information on who looked at what? > Basically every fucking internet users pay the 95th percentile transit to goog…

Seriously. Who would care about a library?

Not everything on the internet is privacy.

And even with https any proxy (WCCP) already knows which URL I went to.

Re: Google Will Soon Shame All Websites That Are Unencrypted

#158
post #39

Yes, shame all libraries/swimming pools giving their schedule online without HTTPS. Shame gutenberg project, the documentations for OS, code, your washing machine. Why would money from libraries gutenberg project, NGOs informations go to more expansive OPEX for web hosting when an information is clearly designed and OK to be public? And does not require adds or payment. Google has some godwin point very authoritative…

What additional money is needed to implement HTTPS? It's like an afternoon of a sysadmin's time; it doesn't require any more opex. If you have a favorite library or NGO that doesn't support HTTPS for lack of funding, I am personally happy to donate an afternoon's of a sysadmin's wages to them. (Or to set it up for them, honestly.) Project Gutenberg is already over HTTPS, so I'm not sure what you mean by that. If you…

Libraries in particular can get help from the Library Freedom Project to set up HTTPS. Some librarians have come to appreciate its importance in protecting information about what library resources (like books) patrons are interested in, for library web sites that allow people to do catalogue searches online, for example.

https://libraryfreedomproject.org/ourwork/digitalprivacypled...

(It's true that that's not the original poster's exact example, which hypothesized a static site that just tells you the library's schedule. But I think library catalogues are a super-great example where information is completely public -- it's not secret what the library has in its collection -- but information about users' interest in that information is private and sensitive, and the people providing the information strongly agree with that concern when they stop to think about it; librarians care very much about not revealing who is interested in which books.)

Re: Google Will Soon Shame All Websites That Are Unencrypted

#159
post #39

Yes, shame all libraries/swimming pools giving their schedule online without HTTPS. Shame gutenberg project, the documentations for OS, code, your washing machine. Why would money from libraries gutenberg project, NGOs informations go to more expansive OPEX for web hosting when an information is clearly designed and OK to be public? And does not require adds or payment. Google has some godwin point very authoritative…

What additional money is needed to implement HTTPS? It's like an afternoon of a sysadmin's time; it doesn't require any more opex. If you have a favorite library or NGO that doesn't support HTTPS for lack of funding, I am personally happy to donate an afternoon's of a sysadmin's wages to them. (Or to set it up for them, honestly.) Project Gutenberg is already over HTTPS, so I'm not sure what you mean by that. If you…

buying a certificate and changing it yourself. So it costs minimum price a certificate, and at least one person competent enough.

And competence in terms of spending is way more than the certificate.

Outsourcing security without knowledge is praying for being abused.

So sometimes you are better in terms of costs and efficiency without.

And HTTPS cost more for rural users because you cannot cache SSL contents.

So in africa, alaska, yukon, peta ouchnok people with small providers have to pay a tax.

And it increases also the 95th percentile.

So basically everybody except google will pay for this but it will impact more the poorest content provider & users.

Re: Google Will Soon Shame All Websites That Are Unencrypted

#160

Consider this: - Squarespace doesn't support SSL (other than on their ecommerce checkout pages) [1] - Weebly only allows it on their $25/mo business plan [2] - Wordpress.com doesn't support SSL for sites with custom domains [3] - If you've never experienced the process of requesting, purchasing, and then installing an SSL certificate using a hosting control panel like Plesk or cPanel, let me tell you–it's a nightmare…

DreamHost now supports Let's Encrypt through their admin panel. The only instructions, however, are a community-maintained wiki page that is already outdated, referring to panel menus that no longer exist. I successfully obtained my certificate, but it was not easy.
Post reply on HN