Live data from Hacker News

Encrypted web traffic now exceeds 90%

netmarketshare.com

171–180 of 311 posts

Re: Encrypted web traffic now exceeds 90%

#171
post #73

We often hear the complaint here that nobody cares / cared about Snowden's revelations. But to me it seems he did provide a lot of the impetus for having HTTPS virtually everywhere and a lot of the instant messenging apps being end-to-end encrypted. Most of WhatsApp's users are as non-technical as it gets, and yet they use the kind of encryption that only computer enthusiasts were interested in just a couple years ag…

If people really listened to Snowden they wouldn't be relying on CA authorities for certificates.

I don't consider a cert trustworthy just because it's signed by a CA, unless that CA is mine or one run by someone I personally know and trust. I came to this position before Snowden, though.

Re: Encrypted web traffic now exceeds 90%

#173

Earlier quoted context omitted.

He was very useful to inform the wider audience about global surveillance, make it "we already know that - boring!" and accelerate the progress of laws to extend it. In the end, this was his mission. edit: thank you for the downvote, well-informed stranger!

19 days before Snowden flew to Hong Kong, former FBI counter-terrorism agent Tim Clemente spilled the beans on CNN[0] (for context, informarion from a phonecall between one of the Boston Marathon bombers and his wife had been leaked to the media): >BURNETT: Tim, is there any way, obviously, there is a voice mail they can try to get the phone companies to give that up at this point. It's not a voice mail. It's just a…

>> I don't feel comfortable saying Snowden is still working for the US government, but I'm certainly suspicious of him.

Well. My deep belief is that individuals that are truly dangerous to the system (here, any system that is powerful enough but one can view it globally as a continuously evolving technology-driven wanna-be-AI) get separated from power asap and then directly eliminated if needed. One should be very naive to think that the following makes any sense: "a young boy from government family says that the whole world is controlled by a few; he wants to stop it and so gets a platform to alarm about it via main media channels, supposedly controlled by the same few". Another point of the whole move was to identify people (e.g., you and me) who will not buy this so they will likely avoid buying other incoming BS.

Re: Encrypted web traffic now exceeds 90%

#174
post #170

Earlier quoted context omitted.

19 days before Snowden flew to Hong Kong, former FBI counter-terrorism agent Tim Clemente spilled the beans on CNN[0] (for context, informarion from a phonecall between one of the Boston Marathon bombers and his wife had been leaked to the media): >BURNETT: Tim, is there any way, obviously, there is a voice mail they can try to get the phone companies to give that up at this point. It's not a voice mail. It's just a…

Snowden released a large collection of documents. Judging by his interview with Joe Rogan, he's a passionate advocate for encryption and says that the US is creating a tool for complete oppression. It's harder to get more apocalyptic than that.

If you want to win against a view, select a leader from your pocket, make him look plausible and make him take control of the whole view. At any point you desire, let that person discredit himself and take the whole view down.

Re: Encrypted web traffic now exceeds 90%

#175
post #155

Earlier quoted context omitted.

It is still better than situation where everyone would use HTTP and naively believe that authorities will respect their right for privacy.

I'd almost prefer to be on http knowing I was insecure than be on https and wrongly believing I was secure.

Well, I don't really trust random certs even when they're signed by a respected CA -- but I still prefer using HTTPS. Even if the cert is fraudulent, HTTPS is still encrypting stuff and will protect me from other random attackers.

Security is never a binary secure/insecure proposition. There are shades of gray. The key is to use what security you can, but never think "I'm secure now".

As an old mentor once told me: the moment that you think you're secure is the moment that you're at the greatest risk, but you should still lock your door.

Re: Encrypted web traffic now exceeds 90%

#177
post #73

We often hear the complaint here that nobody cares / cared about Snowden's revelations. But to me it seems he did provide a lot of the impetus for having HTTPS virtually everywhere and a lot of the instant messenging apps being end-to-end encrypted. Most of WhatsApp's users are as non-technical as it gets, and yet they use the kind of encryption that only computer enthusiasts were interested in just a couple years ag…

Maybe a noob question, but are whatsapp's messages secure from Facebook? Would some motivated employee at Facebook be able to read everyone's messages if they wanted? If no, how do we know?

Re: Encrypted web traffic now exceeds 90%

#178
post #137

I know this is good and all, but it does bum me out that Netscape 4.8 works much worse than it did even a few years ago. I prefer it to iCab, which might fair slightly better. Any suggestions for Mac OS 7.6 web browsers that support the minimum encryption required these days?

My suggestion is to set up a proxy. This has long been necessary to run browsers like Mosaic on the modern web, since many websites are inaccessible from HTTP/1.0 (or earlier!)

It's funny how ever-moving Internet standards mean an Apple II from 40 years ago is more functional than an iMac from 20 years ago.

Re: Encrypted web traffic now exceeds 90%

#179
post #73

We often hear the complaint here that nobody cares / cared about Snowden's revelations. But to me it seems he did provide a lot of the impetus for having HTTPS virtually everywhere and a lot of the instant messenging apps being end-to-end encrypted. Most of WhatsApp's users are as non-technical as it gets, and yet they use the kind of encryption that only computer enthusiasts were interested in just a couple years ag…

Ironically, Telegram markets itself as the most private and secure messenger, but in reality, it's much less private than WhatsApp or Viber: any regular (non-secret) Telegram chats are not end-to-end encrypted - if they were, you wouldn't be able to access them from a new device after authorization with a password.

This marketing message always confused me: my techie understanding was that Telegram is actually one of the least secure messaging choices. If you want security, my understanding is that your preferences should go Signal, Whatsapp, iMessage, Hangouts or whatever Google's flavor-of-the-month messaging app is these days, Telegram, and Facebook.

Re: Encrypted web traffic now exceeds 90%

#180
post #177
post #73

We often hear the complaint here that nobody cares / cared about Snowden's revelations. But to me it seems he did provide a lot of the impetus for having HTTPS virtually everywhere and a lot of the instant messenging apps being end-to-end encrypted. Most of WhatsApp's users are as non-technical as it gets, and yet they use the kind of encryption that only computer enthusiasts were interested in just a couple years ag…

Maybe a noob question, but are whatsapp's messages secure from Facebook? Would some motivated employee at Facebook be able to read everyone's messages if they wanted? If no, how do we know?

If you’re talking about decrypting messages encrypted created and read via SSL (what they imply is the case), it’s not possible unless you have the private key, versus the widely available public key.

I doubt it’s lying around in Facebooks repositories but I’ve never worked there so cannot say that is the case with certainty.

This is all assuming they are even using modern SSL and are careful with user data. Unfortunately, not a great track record there for FB.

Post reply on HN