Live data from Hacker News

HTTPS by default

security.googleblog.com

261–268 of 268 posts

Re: HTTPS by default

#261
post #259

Earlier quoted context omitted.

> Apple even supports Detecting this interception so the operating system Whats it intercepting? Apples detection sends a HTTP/HTTPS request to captive.apple.com. If it fails, it assumes a captive portal. Theres also a DHCP option apple supports. But even after detection, theres redirection. Have a look at WAP Vendor options. Heres Powerlynx explicitly requests disabling HTTPS before auth on Cambium in their user set…

But why do we need to avoid https at all? You can easily have CA-signed certificates and have DNS server resolve the local ourfreewifi.com domain. It’s your domain, you can even set up DNSSEC and it will be fine.

Saves the hotspot portal vendors headaches in debugging. Yes they could (and will be dragged kicking and screaming to do so) just use proxies with certs to intercept traffic but in the short term if they can avoid good practices they will.

Re: HTTPS by default

#262

Earlier quoted context omitted.

The certificate transparency log lets everyone know which domains are active as the certificates are getting renewed, likely more often than the domain itself, and also which sub- domains are active if those are not secured using a wild-card certificate. Not just Google: AI bots could use the information to look for juicy new data to scrape and ingest. Probably not a significant thing, the information can be derived…

This doesn't feel like much of an argument in favor of not using https though.

Not at all IMO, unless you are really paranoid about Google & friends. I was just saying that what was being questioned does (or could) benefit them a tiny bit.

Re: HTTPS by default

#263

Earlier quoted context omitted.

The onion URL is itself a public key - https://protonmailrmez3lotccipshtkleegetolb73fuirgj7r4o4vfu7... for example. Proton Mail burned CPU time until they found a public key that started the way they wanted it to. So that is the public key for an HTTPS equivalent as part of the tor protocol. You can ALSO get an HTTPS certificate for an onion URL; a few providers offer it. But it’s not necessary for security - it does…

If everyone who wants a human readable domain did this, it would environmentally irresponsible. Then 'typo' domains would be trivial. protonmailrmez31otcciphtkl or protonmailrmez3lotcciphtkl. Its a shame these did put in a better built-in human readable url system. Maybe a free form text field 15-20 characters long appended to the public key and somehow be made part of that key. Maybe the key contains a checksum of t…

>If everyone who wants a human readable domain did this, it would environmentally irresponsible

Could we finally stop acting like we know how other people's energy is being produced?

Re: HTTPS by default

#264
post #259

Earlier quoted context omitted.

> Apple even supports Detecting this interception so the operating system Whats it intercepting? Apples detection sends a HTTP/HTTPS request to captive.apple.com. If it fails, it assumes a captive portal. Theres also a DHCP option apple supports. But even after detection, theres redirection. Have a look at WAP Vendor options. Heres Powerlynx explicitly requests disabling HTTPS before auth on Cambium in their user set…

But why do we need to avoid https at all? You can easily have CA-signed certificates and have DNS server resolve the local ourfreewifi.com domain. It’s your domain, you can even set up DNSSEC and it will be fine.

How do you tell iOS/Android which website to open? You do that by hijacking the request to http://captive.apple.com and then 301/302 it to your domain, with or without https. If the first request iOS made was to be secure, you’d have to have a valid certificate for captive.apple.com running in your infrastructure OR the iOS would have to allow self-signed without asking for exceptions. Both sound like a terrible idea.

Re: HTTPS by default

#265
post #113

Https really sucks for our intranet. Every little web app and service needs certificates and you can't use letsencrypt.

You may not want to, but you can use public certs and URLs on your intranet. You can't necessarily do http-01 challenges, but DNS based challenges are feasible. There are also other ACME providers which will let you skip challenges for DCVd domains.

> There are also other ACME providers which will let you skip challenges for DCVd domains

Do you have examples? I’m not sure how to search for this feature.

Re: HTTPS by default

#266

I have had HTTPS-by-default for years and I can say that we're past the point where there's noticeable year-to-year change for which sites aren't HTTPS. It's almost always old stuff that pre-dates Let's Encrypt (and presumably just nobody ever added HTTPS). The news site which stopped updating in 2007, the blog somebody last posted to in 2011, that sort of thing. I think it's important to emphasise that although Tim'…

I don't like this change. There are a lot of SaaS business that allow you to create a CNAME along the lines of "saas_app_name.yourbusiness.com". For example Fastmail and Zoho do that, our business offers that feature as well. When you arrive at our site we do a redirect to a proper https URL. But a browser will not accept a redirect from a domain with an incorrect certificate (and rightly so), so this will start fail…

Sounds like a big excuse.

Re: HTTPS by default

#267

Earlier quoted context omitted.

Right now it only shows a little bubble in the URL bar saying "Not Secure", I think. (So, that is a "warning", in a sense.) TFA is saying there will now be an interstitial if you attempt an HTTP connection. HSTS might also interact with this, but I'd expect an HSTS site to just cause Chrome to go for HTTPS (and then that connection would either succeed or fail). > to force network-level auth flows (which don't always…

I don’t believe Android IPv6 stack supports dhcp, so won’t be much use there.

IPv6 RAs also support prompting the client about captive portals similarly, too, I think.

(But also at some point that seems like a bug in Android.)

Re: HTTPS by default

#268

Earlier quoted context omitted.

I run my blog in unencrypted HTTP/1.1 just to make a point that we do not have to depend on third parties to publish content online. And I noticed that Whatsapp is even worse than Chrome, it opens HTTPS even if I share HTTP links.

That's a good point to make, IMHO What is funny about HTTPS is that early arguments for its existence IIRC were often along the lines of protecting credit card numbers and personal information that needed to be sent during e-commerce HTTPS may have delivered on this promise. Of course HTTPS is needed for e-commerce. But not all web use is commercial transactions Today, it's unclear who or what^2 HTTPS is really prote…

O5QXGIBLGEQHI2DFNYQGI33XNYQHI2DFNYQHK4BAORUGK3RAMRXXO3QK
Post reply on HN