Live data from Hacker News

Deprecating Non-Secure HTTP

blog.mozilla.org

241–250 of 318 posts

Re: Deprecating Non-Secure HTTP

#241

Earlier quoted context omitted.

It has become so tiresome to deal with the likes of you - people who will say how they don't need or want SSL, how they don't care about privacy. This is the techie version of "nothing to hide, nothing to fear". It's a pathetic argument and brings nothing to the table. Just because you don't care about the NSA knowing you like McDonalds when you browse their menu, everybody else in the world shouldn't care about thei…

A shame that's not the argument at all - what is being argued against is the chipping away of HTTP, not implementation of HTTPS.

One can't happen without the other.

Re: Deprecating Non-Secure HTTP

#242
post #238

Earlier quoted context omitted.

Well, if cost is your main priority, then startssl.com is the obvious way to go, since it provides free certificates. This "certificates are expensive" argument was only valid a decade ago, we have free certs now.

Free as long as you never have to revoke them. Which means people primarily looking at costs are actually incentived to not revoke compromised certs.

Which is still waaaay better if they ran HTTP.

Re: Deprecating Non-Secure HTTP

#243

Earlier quoted context omitted.

Nope. The goal is to make running a server only available to corporate entities. It reduce competition from folks like yourself.

What in your life must have happened for you to actually believe such nonsense? Or do you have a financial incentive of sorts to try to make other people believe it?

Well, in this case:

1. The technical solution is trivial. You always have encryption, but http=self-signed cert, and no authentication, and no lock icon. https=CA cert, encryption, authentication, and lock icon.

2. There are strong government and corporate interests in being able to filter the open web. This closes the open web.

3. For the first time in my life, I have a comment on Hacker News or Reddit at -4. I've posted much more controversial things before (I do care about anonymity; I do use one-off cypherpunks accounts, so my post history won't indicate things). Good debate was virtually always well-received, up-voted, and not censored. The only exception was here, and one place where there was a strong, clear, well-financed astroturf campaign. That's one datapoint, but overall, the debate on the topic smells of financed astroturf rather than genuine grassroots.

Re: Deprecating Non-Secure HTTP

#244
post #223
post #204

Earlier quoted context omitted.

That is today's prices, based past demand. As demand for SSL hosting goes up, gradually replacing plaintext hosting, the price will come down. I actually expect the price of plaintext HTTP hosting to go up a bit; partly due to reduced demand, but also due to increased risk/liability. With SSL being the "industry best practice", I expect at least a few bean counters will view the risk of private information leaks or h…

Demand going up does not always mean that pricing goes down. Especially when supply is limited

Obviously. What's your point? That the price of SSL hosting will stay the same? Go up? I never claimed it would equalize perfectly, just that it would get cheaper in the future.

Also, why do you think the supply of SSL hosting services is necessarily limited any more than traditional plaintext hosting would be?

Re: Deprecating Non-Secure HTTP

#245

I have to say, I actually disagree with this move. While I think the intentions sound noble, and I'm all for a more secure web, I also believe that a web browser has no business dictating that the entire web should be forced in HTTPs. I don't see any benefit in this type of blanket, all or nothing, type of approach. In fact, I see it doing more damage than good. Encrypting blogs, news websites, etc still makes no sen…

> I don't see any benefit in this type of blanket, all or nothing, type of approach.

Imagine you're making some meatballs. You've got pigs, spices, and a stove.

If you're in Germany, there's no problem -- kill some pigs, grind some pork, mix in the spices, and cook your meatballs. You could make sausages the same way (as long as you've got tubing). And you're free to sample your food as you cook it to make sure it suits your tastes.

If you're in the US, you've got two options:

1. Give up on sausage entirely. Make sure your ground pork is well cooked before you even think of eating any of it.

2. Carefully vet the pigs for trichinosis before introducing their pork into your kitchen.

Unsurprisingly, we use option 1.

Germany, like the rest of Europe, has opted for a blanket solution where they're not allowed to have pigs with trichinosis. The US has opted for a different blanket solution where you can't eat raw pork. Nobody is suggesting that we carefully inspect individual pigs and treat the meat according to whether they had trichinosis.

Re: Deprecating Non-Secure HTTP

#246
post #107

If you really want to tackle SSL make it less stupid. Self-signed certificates? I want these pinned and treated as secure. I want a notification if they change around the time they expire and a really big warning if they don't. If we must have central trust sources, then have central hash servers so when I visit a new self-signer I can externally verify the hash.

How is a central has server, which could be blocked by an attacker or simply be down, better than having a central authority sign my certificate?

Re: Deprecating Non-Secure HTTP

#247

Earlier quoted context omitted.

Off the top of my head: the bashing of Rob Graham, the defense of concepts that have nothing to do with our rights on the Internet, such as feminism.

I just spent several minutes googling for "EFF" in conjunction with "feminism" and didn't find anything that appeared to be relevant. I did the same for Rob Graham, and he apparently doesn't like the EFF, but I haven't found the EFF saying anything about him yet. I'm sure someone associated with the EFF has mentioned these things at some point, but they don't appear to be major issues. Could you give me some links?

Don't feed the trolls. I don't think his contributions to this thread warrant further discussion.

Re: Deprecating Non-Secure HTTP

#248

Earlier quoted context omitted.

Seriously, SSLs basically 2x the hosting cost for low end hosting packages. Not great for people running small websites.

SSL should be a universally available free resource. I expect that it will be in the near future. That said, it is still very cheap for small sites too: $9 - $11 / year for perfectly good certs. Less than $1 per month is a small burden. https://www.namecheap.com/security/ssl-certificates/domain-v...

>$9 - $11 / year for perfectly good certs

So long as you don't need any subdomains, right?

Re: Deprecating Non-Secure HTTP

#249
post #203
post #99

Here's two relevant Bugzilla bugs: Self-signed certificates are treated as errors: https://bugzilla.mozilla.org/show_bug.cgi?id=431386 Switch generic icon to negative feedback for non-https sites: https://bugzilla.mozilla.org/show_bug.cgi?id=1041087 Here's a proposed way of phasing this plan in over time: 1. Mid-2015: Start treating self signed certificates as unencrypted connections (i.e. stop showing a warning, but…

Why the hate for self-signed certificates? I would personally rather see those promoted and methods developed to securely bootstrap them than make us all reliant on centralised CA infrastructure. The centralised CAs are all at the mercy of their governments and hence, in my opinion, ought to be considered almost as insecure as self-signed certs. EDIT: I think I misunderstood your comment - reading again it sounds lik…

Until supports for DANE and DNSSEC becomes widespread, unless it's a site for personal use, self-signed certs can't really be trusted by third parties.

(BTW, if you're not using a conventional CA, you'd best off being your own CA, and signing your certs with a CA certificate you've generated rather than simply self-signing the cert. It's a little more trouble in the short term, but it means that each time you subsequently need to generate a new cert, you don't need to put up with warnings everywhere because it'll be validated by your own CA cert. The downside of this is having to install the CA cert everywhere. That's what I do for my private stuff. There are tonnes of tutorials online on how to do it.)

Post reply on HN