Live data from Hacker News

Encrypted web traffic now exceeds 90%

netmarketshare.com

191–200 of 311 posts

Re: Encrypted web traffic now exceeds 90%

#191
post #183
post #73

We often hear the complaint here that nobody cares / cared about Snowden's revelations. But to me it seems he did provide a lot of the impetus for having HTTPS virtually everywhere and a lot of the instant messenging apps being end-to-end encrypted. Most of WhatsApp's users are as non-technical as it gets, and yet they use the kind of encryption that only computer enthusiasts were interested in just a couple years ag…

It is a very fair point that Snowden's revelations definitely had an impact. However, the impact you note was mostly technical. The public backlash to these revelations is what seems lacking. It had very small political effects, and seemingly very little effect on the NSA. They did not change their stance much, and their weren't really consequences for what the NSA was doing.

What’s more important though? The public can’t particularly change things at that level. They don’t live at that level. It’s our job to help them. Just as they help me on non computer related stuff all the time. A barber shouldn’t be in charge of web encryption. It’s on us.

Re: Encrypted web traffic now exceeds 90%

#192
post #162

Earlier quoted context omitted.

Ironically, Telegram markets itself as the most private and secure messenger, but in reality, it's much less private than WhatsApp or Viber: any regular (non-secret) Telegram chats are not end-to-end encrypted - if they were, you wouldn't be able to access them from a new device after authorization with a password.

They don’t claim end to end encryption by default though. You make it sound as if there is a revelation you made here. Telegram has faults, I would even argue it has many, but it’s clear that only “secret” chats and voice/video calls are end to end encrypted. Whatsapp, however, does allow you to download all of your messages from your device using WhatsApp web, and they were recently shown to have an exploit/backdoor…

Whatsapp also doesn't encrypt backups to icloud, which it nags you to turn on.

Re: Encrypted web traffic now exceeds 90%

#193
post #20

Awesome! Any idea how much of that is attributable to LetsEncrypt and HTTPSEverywhere?

Is a LetsEncrypt certificate "just as secure" as other certs? I have to imagine the answer is "no" simply because LetsEncrypt is free and the other certs aren't -- what more do you get by paying for a cert?

Thing is, even if LetsEncrypt were less secure (I don't really think it is, but lets assume), that would hurt the security of every website.

If you use a paid CA, someone trying to impersonate you could still go to lets-encrypt and get a certificate there. In other words, the system is only ever as secure as its weakest link. It doesn't matter what link you chose, it matters what link a potential attacker would use.

All of this is because failure of a CA only means false certificates are issued. Its not like lets encrypt ever could get access to any of your private key material.

Re: Encrypted web traffic now exceeds 90%

#195
post #126

Earlier quoted context omitted.

And even if they get a key, they will show up in the CT Logs eventually and the attack becomes public.

The effectiveness of CT logs isn't a thing unless the website uses CT monitoring or is a huge company. A [delegated or non-delegated] DNS takeover, or IP address release (eg. cloud providers re-assigning an IP to another customer) could allow you to generate a certificate for some-forgotten-subdomain.medium-sized.company.com using the ACME http challenge. Of course this is mitigated by properly managing your DNS, and…

In other words, the effectiveness of the CT logs is a thing. There are multiple services which will do this for you for free (Cloudflare and Facebook at least make it trivial to get notifications for your domains) and it’s a level of visibility which almost nobody had just a few years ago.

Re: Encrypted web traffic now exceeds 90%

#196

Earlier quoted context omitted.

If people really listened to Snowden they wouldn't be relying on CA authorities for certificates.

I don't consider a cert trustworthy just because it's signed by a CA, unless that CA is mine or one run by someone I personally know and trust. I came to this position before Snowden, though.

In the CA model is anything 100% yours? A signed cert has to depend on someone you dont know.

Re: Encrypted web traffic now exceeds 90%

#197
post #169

Earlier quoted context omitted.

To add to the irony: Telegram has evolved in a bit of a darknet on its own where people casual share content that would be near impossible to find on the surface web.

how do I get in on this?

First rule of fight club

Re: Encrypted web traffic now exceeds 90%

#199

I’m sorry, but there’s a lot of smart people here. Why is everyone assuming HTTPS means no one is snooping? I presume someone is snooping no matter what.

Snooping on Https requires significant resources. Snooping on http is very cheap. A good analogy is locking your door. Sure, can be dealt with. But most would be criminals won't go further than twisting the door knob.

Re: Encrypted web traffic now exceeds 90%

#200

Earlier quoted context omitted.

Ironically, Telegram markets itself as the most private and secure messenger, but in reality, it's much less private than WhatsApp or Viber: any regular (non-secret) Telegram chats are not end-to-end encrypted - if they were, you wouldn't be able to access them from a new device after authorization with a password.

This marketing message always confused me: my techie understanding was that Telegram is actually one of the least secure messaging choices. If you want security, my understanding is that your preferences should go Signal, Whatsapp, iMessage, Hangouts or whatever Google's flavor-of-the-month messaging app is these days, Telegram, and Facebook.

I was following you until Hangouts...
Post reply on HN