Live data from Hacker News

Deprecating Non-Secure HTTP

blog.mozilla.org

281–290 of 318 posts

Re: Deprecating Non-Secure HTTP

#281

Earlier quoted context omitted.

It's hardly rocket surgery though. Anyone incapable of following the steps required there is probably not who you'd want implementing your web server security…

That's the entire point. If the whole web is going to be secure, then someone who "is not who you'd want implementing your web server security" needs to be able to make it work, and work right.

I believe let's encrypt is supposed to be a single command to run. Anyone that can set up a webserver can manage it.

If you're going the minimally technical route then you're using shared or managed hosting and it's not your job to set up the SSL.

Re: Deprecating Non-Secure HTTP

#282
post #165
post #162

Earlier quoted context omitted.

The proposal says: > That would allow things like CSS and other rendering features to still be used by insecure websites ... [but] restrict qualitatively new features, such as access to new hardware capabilities ... [like] persistent permissions for camera and microphone access If accessing my camera over an insecure connection is your definition of doing interesting things, I would be happy to block you. In fact, I…

You changed your opinion quickly. Previously you said: > The plan is to disable some of the "more dangerous" features when the page is requested over HTTP And now you're saying that every new feature falls into this category. Listen, I'm all for going all-in on SSL. What I'm not for is doing until SSL is as seamless and inexpensive as HTTP. What really concerns me is that the https-only nazis do not share this concer…

>And now you're saying that every new feature falls into this category.

Subtle misreading. It's not that new features are in that category by definition, it's that every major feature proposal kijin has seen so far has been of the dangerous sort.

Re: Deprecating Non-Secure HTTP

#283
post #155

Earlier quoted context omitted.

Why is compromise of a cert that can sign " .moo.bar.foo.baz.com" so* much worse than compromise of one that can sign "www.moo.bar.foo.baz.com"?

The compromise of technet.microsoft.com, while a very big deal, would be an order of magnitude worse if it was *.microsoft.com.

How so? The update mechanisms use certificate pinning, and even if they didn't it sounds like an argument to use different certificates for code signing and for web servers. What other problems could there have been? Most people are only going to verify that it's microsoft.com.

Re: Deprecating Non-Secure HTTP

#284
post #119

Earlier quoted context omitted.

One thing I've never been able to figure out from Let's Encrypt's website - will you be able to get a certificate, without hosting your own instance? Or will it be limited to servers you can actually install their program on? Also, I assume they'll get the root CA included by all major vendors/browsers?

You don't have to run the Let's Encrypt client, but you do have to be able to do things to prove that you control the domain. Currently the Let's Encrypt client assumes that it's being run on the same machine on which domain control will be proved (though not necessarily the same machine where the cert will eventually be deployed). Someone could write another client application which gives instructions to complete th…

So you don't have to run the Let's Encrypt client? I was under the impression you did because without running the client there was no way to communicate with the Let's Encrypt service?

Or do you mean, you can have multiple servers and only need to run the client on one of them?

Re: Deprecating Non-Secure HTTP

#285
post #255

Earlier quoted context omitted.

HTTPS provides authentication, not just confidentiality. When you visit "blogs, news websites, etc" do you think there's no value in being able to know for sure that the content is exactly what the owner of the site intended? Even though ISPs have proven themselves willing to intercept and modify that content in transit? http://arstechnica.com/tech-policy/2013/04/07/how-a-banner-a... http://arstechnica.com/tech-polic…

But https doesn't 'let you know for sure that the content is exactly what the owner of the site intended' as it doesn't protect you from xss

Than you fix the XSS vulnerabilities and implement CSP. Shitty security practices is not an excuse for more shitty security practices. https://developer.mozilla.org/en-US/docs/Web/Security/CSP

Re: Deprecating Non-Secure HTTP

#286

Earlier quoted context omitted.

That's just one project, and it doesn't even exist yet. The web is moving faster every day, apparently. I sure do hope that project will be all it's chalked up to be. For example, I need IP-only certs for a new project I'm working on (waiting for DNS to propagate to all clients is too unreliable and slow). If letsencrypt doesn't do that... well then I'd have to hope real hard for a competent CA out there who has an a…

For example, I need IP-only certs for a new project I'm working on (waiting for DNS to propagate to all clients is too unreliable and slow). This doesn't make any sense. You're not waiting for DNS to propagate to clients; if anything you're waiting for recursive DNS servers at shitty ISPs to time out their caches when they are configured to not honor the RR's TTL sent by the authoritative server in a misguided attemp…

[deleted]

Re: Deprecating Non-Secure HTTP

#287

Earlier quoted context omitted.

Can someone explain why we can't give SSL certificates along with domain registration? We already trust the DNS, don't we?

The original idea with SSL was to give out certificates to organizations, not domain holders. The labour involved made this an expensive process and today domain validated certificates are the most common. The idea was that users should want to validate they speak with the organization McDonald's, not with mcdonalds.com which may or may not belong to them. Turns out users don't, and that the distinction gets even les…

> The original idea with SSL was to give out certificates to organizations, not domain holders.

FYI that's exactly what EV SSL does now - hence the company checks, and the green bar:

Eg, here's a regular certificate

   openssl x509 -in example.com.crt -noout -text | grep Subject
   Subject: 1.3.6.1.4.1.311.60.2.1.3=GB/businessCategory=Private Organization/serialNumber=09378892, C=GB, ST=City of London, L=London, O=example Limited, CN=billing.example.com, DNS:billing.example.com, DNS:www.billing.example.com
https://certsimple.com/blog/do-ev-ssl-certificates-have-bett...

Re: Deprecating Non-Secure HTTP

#288
post #220

Earlier quoted context omitted.

Well you still depend on 3rd parties to register a domain. And one to provide a connection, if not a server.

/etc/hosts when I was experimenting with computers I had a WAMP executable on my LAN. less parties involved the better.

Localhost will not be restricted. If you're making people edit their hosts file you can make them bypass any security warnings.

Re: Deprecating Non-Secure HTTP

#289

Earlier quoted context omitted.

I just spent several minutes googling for "EFF" in conjunction with "feminism" and didn't find anything that appeared to be relevant. I did the same for Rob Graham, and he apparently doesn't like the EFF, but I haven't found the EFF saying anything about him yet. I'm sure someone associated with the EFF has mentioned these things at some point, but they don't appear to be major issues. Could you give me some links?

Feminism: most of their staff are feminists. I'm not going to spend my time googling and posting links. Here's a start https://www.eff.org/about/staff Rob Graham was called out in this article which was subsequently edited: https://twitter.com/ErrataRob/status/553716844650307584 Also, they lie constantly, in lousy attempts of populism and being lavished with attention: http://blog.erratasec.com/2014/07/eff-lies-about…

Rob Graham seems to like free markets (great) but think US cable companies are a free market (plainly wrong). Thus he thinks that it's a bad idea to protect the internet free market from the cable monopolies. It's a noble cause, he's just not well informed.

Their staff might be feminists, but that doesn't mean they engage in gender discrimination. If you have something better, post it.

Re: Deprecating Non-Secure HTTP

#290

Earlier quoted context omitted.

Can someone explain why we can't give SSL certificates along with domain registration? We already trust the DNS, don't we?

A certificate given by the domain registrar makes a lot of sense to me. My registrar holds my data and indeed can certify the identity of the domain.

There's also a payment-mechanism already in place, and correspondingly users' expectations. They also know where the domain is actually hosted.
Post reply on HN