Live data from Hacker News

Encrypted web traffic now exceeds 90%

netmarketshare.com

181–190 of 311 posts

Re: Encrypted web traffic now exceeds 90%

#181
post #73

We often hear the complaint here that nobody cares / cared about Snowden's revelations. But to me it seems he did provide a lot of the impetus for having HTTPS virtually everywhere and a lot of the instant messenging apps being end-to-end encrypted. Most of WhatsApp's users are as non-technical as it gets, and yet they use the kind of encryption that only computer enthusiasts were interested in just a couple years ag…

We need to promote the use of messaging apps which default to SSL. It shows a user-focused product and perhaps a healthy company.

Re: Encrypted web traffic now exceeds 90%

#182

Earlier quoted context omitted.

Pretty much this. I ran into a local store taking credit cards awhile back, no TLS, weird, so I go to the store owner in person. I explain the problem and he insists that can't be the case, he's mad at me. "See! It's got a lock on the website!"... on the homepage. I direct him to the store and now it says Not Secure. That did more to explain the situation than my attempt at TLS and HTTPS and Certs. He was able to cal…

If that doesn't work, there's also the argument that "credit card providers require it, and could stop you from taking credit cards until you fix it".

this is what gave us the pay.reddit.com loophole back when reddit https was for people with gold only

Re: Encrypted web traffic now exceeds 90%

#183
post #73

We often hear the complaint here that nobody cares / cared about Snowden's revelations. But to me it seems he did provide a lot of the impetus for having HTTPS virtually everywhere and a lot of the instant messenging apps being end-to-end encrypted. Most of WhatsApp's users are as non-technical as it gets, and yet they use the kind of encryption that only computer enthusiasts were interested in just a couple years ag…

It is a very fair point that Snowden's revelations definitely had an impact. However, the impact you note was mostly technical.

The public backlash to these revelations is what seems lacking. It had very small political effects, and seemingly very little effect on the NSA. They did not change their stance much, and their weren't really consequences for what the NSA was doing.

Re: Encrypted web traffic now exceeds 90%

#184
post #162

Earlier quoted context omitted.

Ironically, Telegram markets itself as the most private and secure messenger, but in reality, it's much less private than WhatsApp or Viber: any regular (non-secret) Telegram chats are not end-to-end encrypted - if they were, you wouldn't be able to access them from a new device after authorization with a password.

They don’t claim end to end encryption by default though. You make it sound as if there is a revelation you made here. Telegram has faults, I would even argue it has many, but it’s clear that only “secret” chats and voice/video calls are end to end encrypted. Whatsapp, however, does allow you to download all of your messages from your device using WhatsApp web, and they were recently shown to have an exploit/backdoor…

> They don’t claim end to end encryption by default though. You make it sound as if there is a revelation you made here.

They don't claim e2e encryption by default, they just use some very tricky words that non-technical users will assume as encryption.

From telegram.org:

"Private: Telegram messages are heavily encrypted and can self-destruct."

"Secure: Telegram keeps your messages safe from hacker attacks."

"Encrypt personal and business secrets."

Re: Encrypted web traffic now exceeds 90%

#185
post #73

We often hear the complaint here that nobody cares / cared about Snowden's revelations. But to me it seems he did provide a lot of the impetus for having HTTPS virtually everywhere and a lot of the instant messenging apps being end-to-end encrypted. Most of WhatsApp's users are as non-technical as it gets, and yet they use the kind of encryption that only computer enthusiasts were interested in just a couple years ag…

Agree Snowden is significant because he was able to encourage enough people to INSIST on strong privacy/encryption. Then it all comes down to basic game theory. Why would a company ever want to release any product without strong encryption (end-to-end) when users never complain about their data being encrypted. The only reason companies don't encrypt is when they have a vested interest in spying, either in their own…

I don't think I know many people who insisted on strong privacy/encryption. However, after the Snowden revelations people did consider it a preference. In that sense, it helped.

Re: Encrypted web traffic now exceeds 90%

#186

Earlier quoted context omitted.

Several reasons: - The good is not the enemy of the perfect. - This eliminates an entire class of attacks, namely, man-in-the-middle. - A lot of (most?) user interactions require the server to know what the user wants, and it's unclear how this can happen if the server can't view the user's data.

MITM is not mitigated at all by HTTPS. What makes you think that? Do you understand how certificate signing works?

Literally the only reason TLS uses certificates is to mitigate Man-in-the-Middle attacks.

Establishing a shared secret with another party over a public channel is not that hard (Diffie-helman, RSA). The hard part is to ensure the other party is who they say they are. Certificates tackle this by having a trusted party (CA) cryptographically bind the shared secret to an identity.

There are issues here, but if you can read and modify the traffic between my PC and the HN servers, you still won't be able to read and modify the traffic.

Re: Encrypted web traffic now exceeds 90%

#187
post #90
post #77

Earlier quoted context omitted.

You're not wrong, but the realistic alternative is having it the same way, just without any encryption.

Yes but in this case caching proxies and other distributed approaches still would work out of the box as alternatives to cdns. I am not sure what I have gained. Nobody cares about end to end email encryption. This would be a real benefit, but Google could not build profiles so easily...

> Nobody cares about end to end email encryption. This would be a real benefit, but Google could not build profiles so easily...

AFAIK google states (in their privacy policy) they do not do anything with the contents of your emails in a gmail account.

Re: Encrypted web traffic now exceeds 90%

#188
post #170

Earlier quoted context omitted.

19 days before Snowden flew to Hong Kong, former FBI counter-terrorism agent Tim Clemente spilled the beans on CNN[0] (for context, informarion from a phonecall between one of the Boston Marathon bombers and his wife had been leaked to the media): >BURNETT: Tim, is there any way, obviously, there is a voice mail they can try to get the phone companies to give that up at this point. It's not a voice mail. It's just a…

Snowden released a large collection of documents. Judging by his interview with Joe Rogan, he's a passionate advocate for encryption and says that the US is creating a tool for complete oppression. It's harder to get more apocalyptic than that.

I listened to that interview, and purposefully didn't include my take on it above because I didn't want my crazier belief to distract from my crazy belief. Let's dive into the deep end of my personal crazypool: he came off very politicany to me, even down to the purposeful missteps. People trust a speaker more when the speaker says something a little bit offensive, probably because it's a sign that the person will speak their mind regardless of what anybody else thinks. That moment where he said that no judge would refuse to sign a warrant for "Abu Jihad" or "Boris Baddenov" looked just like this to me -- it's offensive, but immediately juxtaposes an offensive faux-Muslim name with an offensive faux-Russian name, and it's weirdly still socially acceptable to make fun of Russians this way while the Muslim statement is not socially acceptable, so any in-depth discussion of the faux pas can get bogged down unpacking the distinction between these two and making the Muslim characiture seem more understandable in context. The bit where he keeps pulling Rogan away from specific lines of questioning in the beginning, not to avoid them but instead to tell his whole life story leading up to the leaks, seemed like the sort of thing an aspiring politician would do when presented with a microphone and a long format. He acted like his first book had to be autobiographical because the publisher insisted on it, but really, we all know Snowden could find a publisher for a non-autobiographical book. It's an obvious deception; he wants to familiarise the public with his personal story while also acting like he isn't trying to do that. If Snowden gets pardoned sometime between 2024 and 2032 and subsequently makes a run for President, I'm gonna be scared that one of the TLAs has a mole at the top of the one-eyed pyramid.

I'm not making any conspiratorial claims about this part, but as an aside it was weird to me that he claimed cellphone IMEIs can't be changed. It's not normally done, but it can be. I wasn't sure if that was dumbed down for Rogan's audience, a misspeak, or actual ignorance on Snowden's part.

Re: Encrypted web traffic now exceeds 90%

#189
post #126

Earlier quoted context omitted.

...do you? Unless the attacker has access to the private key associated with the SSL certificate, they can't read any HTTPS traffic encrypted via that certificate - mitigating the ability of that bad actor to perform a MITM attack.

And even if they get a key, they will show up in the CT Logs eventually and the attack becomes public.

The effectiveness of CT logs isn't a thing unless the website uses CT monitoring or is a huge company. A [delegated or non-delegated] DNS takeover, or IP address release (eg. cloud providers re-assigning an IP to another customer) could allow you to generate a certificate for some-forgotten-subdomain.medium-sized.company.com using the ACME http challenge. Of course this is mitigated by properly managing your DNS, and CT monitoring is encouraged everywhere.

Re: Encrypted web traffic now exceeds 90%

#190

Earlier quoted context omitted.

The above poster is still technically correct though, getting the cert is just 1 more obstacle in the way of the attack, which isn't as much of an obstacle as one would think for some actors(see China).

Certificate transparency would make it blatantly obvious if Chinese CAs were issuing bogus certificates. (And if they issued certs without submitting them to CT logs they wouldn't be accepted by Chrome or Safari, so it wouldn't be very useful.) Sure, they could do it, but it wouldn't be long until there were no Chinese CAs trusted by any browser.

An attack like this could still be done for CLI clients/library clients such as curl (ie. server-to-server connections), none of which I'm aware of incorporate CT log verification.
Post reply on HN