Earlier quoted context omitted.
Third party root servers are generally used for looking up TLD nameservers, not for looking up domainnames registered to individuals publishing personal blogs^1 Fortunately, one can publish on the www without using ICANN DNS For example http://199.233.217.201 or https://199.233.217.201 1. I have run own root server for over 15 years An individual cannot even mention choosing to publish a personal blog over HTTP witho…
You have some weird definition of "root".
HTTPS by default
191–200 of 268 posts
Re: HTTPS by default
#192Earlier quoted context omitted.
There are dozens of us I guess that care about this kind of thing. I have never really understood the obsession with https for static content that I don't care if anyone can see I am reading like a blog post. HTTPS should be for things that matter, everything else can, and think should use HTTP when it is not necessary. Depending on yet another third party to provide what is IMHO a luxury should not be required, and…
Agreed. I think that the push to make everything HTTPS is completely unnecessary, and in fact counterproductive to security. By throwing scary warnings in front of users when there is no actual security threat, we teach users that the scary warnings don't matter and they just should click past them. Warning when a site doesn't use TLS is a clear cut case of crying wolf.
Re: HTTPS by default
#193Earlier quoted context omitted.
The threat model of HTTP isn't site owners, it's that anyone else can change the content and you can't tell that it didn't come from the original site. It's not a strawman, it's a real attack that we've seen for decades. The entire guidance of "don't connect to an open wireless AP"? That's because a malicious actor who controlled the AP could read and modify your HTTP traffic - inject ads, read your passwords, update…
I call this the quicksand theory of network security. The threat is real but the risk overstated by orders of magnitude.
Now imagine if we still lived in a world like that. Someone visits UN meeting and the rest is your imagination.
[1] https://nordvpn.com/cybersecurity/glossary/firesheep/?srslti...
Re: HTTPS by default
#194Earlier quoted context omitted.
The problem is not the site, but the network in the middle. On-path attackers typically don't care about which site they MITM in order to inject javascript e.g. to show ads, insert tracking tokens or hijack the browser for other purposes. The site is the vector, not the target.
Sounds like a great argument for keeping js disabled in my browser. Because "httpS://" does nothing whatever to sanitize the js that it delivers. And one perfectly legit site may pull in js from two dozen or more different servers. Zero of which are magically guaranteed to only deliver benevolent code. Vs. `traceroute` suggests that would-be on-path attackers are up against a vastly smaller attack surface.
Re: HTTPS by default
#195This is to be honest a little unfortunate. While Https is very important, do we really need to verify that Blog X that I may read once a year is really who they say they are? For many sites it doesn't make a lot of sense but we are here due to human nature
The problem is not the site, but the network in the middle. On-path attackers typically don't care about which site they MITM in order to inject javascript e.g. to show ads, insert tracking tokens or hijack the browser for other purposes. The site is the vector, not the target.
Re: HTTPS by default
#196Earlier quoted context omitted.
The threat model of HTTP isn't site owners, it's that anyone else can change the content and you can't tell that it didn't come from the original site. It's not a strawman, it's a real attack that we've seen for decades. The entire guidance of "don't connect to an open wireless AP"? That's because a malicious actor who controlled the AP could read and modify your HTTP traffic - inject ads, read your passwords, update…
Then perhaps the problem is open APs? There are still legitimate uses for HTTP including reading static content. Say we all move to HTTPS but then let’s encrypt goes away, certificate authority corps merge, and then google decides they also want remote attestation for two way trust or whatever - the whole world becomes walled up into an iOS situation. Even a good idea is potentially very bad at the hands of unregulat…
Just switch to ZeroSSL - it's the default certificate provider for the acme.sh script now.
Re: HTTPS by default
#197Earlier quoted context omitted.
I don't get your logic/reasoning here... could you explain?
There are public logs of every TLS cert issued by the major providers. This benefits Google. Kinda like how Wikipedia benefits Google. Or public roads benefit Uber. Or clean water benefits restaurants
Re: HTTPS by default
#198Earlier quoted context omitted.
If someone is in your LAN then you have bigger problems than them snooping on you while you talk to your fridge.
Like eBay? Slightly different https://nullsweep.com/why-is-this-website-port-scanning-me/
Re: HTTPS by default
#199Earlier quoted context omitted.
While Google and friends are happy to push for https, it’s dramatically easier to scam people via ads or AI generated content. Claiming plain HTTP is scary seems like a straw man tbh
The threat model of HTTP isn't site owners, it's that anyone else can change the content and you can't tell that it didn't come from the original site. It's not a strawman, it's a real attack that we've seen for decades. The entire guidance of "don't connect to an open wireless AP"? That's because a malicious actor who controlled the AP could read and modify your HTTP traffic - inject ads, read your passwords, update…
Re: HTTPS by default
#200Earlier quoted context omitted.
>usually making your own car is legal It may be legal but good luck ever getting registration for it.
It's actually not that bad in most states, some even have exceptions to emissions requirements for certain classes of self-built cars. Now, getting required insurance coverage, that can be a different story. Btu even there, many states allow you to post a bond in lieu of an insurance policy meeting state minimums.
It’s trying to make and sell three or four that is nearly impossible.