Did he really dismiss the huge benefit of https that my browser is guaranteed to receive the exact content that the site owner sent me, with an idiotic argument that while it prevents Starbucks or Comcast from pwning me, it doesn't prevent the browser. Really?
Google and HTTP
31–40 of 63 posts
Re: Google and HTTP
#32Did he really dismiss the huge benefit of https that my browser is guaranteed to receive the exact content that the site owner sent me, with an idiotic argument that while it prevents Starbucks or Comcast from pwning me, it doesn't prevent the browser. Really?
Re: Google and HTTP
#33Earlier quoted context omitted.
That's what I was referring to. I don't understand what you don't understand about the reference.
Displaying a warning to users doesn't make sites "inaccessible".
Re: Google and HTTP
#34Earlier quoted context omitted.
I was referring specifically to the author's claim that deprecating HTTP and displaying a warning to users is the equivalent of "rendering large parts of the web inaccessible" and "massive book burning".
If you mark something as 'Not Secure' you're effectively telling users not to access it. It doesn't matter in practice if the content is still accessible when the browser tells people that accessing it is dangerous. A lot of content that exists on the unmaintained web is going to effectively be lost, and maybe that's okay because the benefits are worth it, but that's the argument that needs to be made.
It certainly does matter. There's a fundamental different between people being discouraged from accessing a website, and said website being completely inaccessible.
Re: Google and HTTP
#35Earlier quoted context omitted.
I was referring specifically to the author's claim that deprecating HTTP and displaying a warning to users is the equivalent of "rendering large parts of the web inaccessible" and "massive book burning".
If you mark something as 'Not Secure' you're effectively telling users not to access it. It doesn't matter in practice if the content is still accessible when the browser tells people that accessing it is dangerous. A lot of content that exists on the unmaintained web is going to effectively be lost, and maybe that's okay because the benefits are worth it, but that's the argument that needs to be made.
A migration of newer websites to HTTPS is no more a loss to data than deprecating old versions of HTML in newer versions of Chrome or upgrading newer servers to HTTP/2. The old ones will still exist. And if they cease to exist, it's almost certainly not going to be because a browser displays a "not secure" warning on the top left corner of the scene.
There are also entire websites and communities built upon the archival of data:
Re: Google and HTTP
#36Earlier quoted context omitted.
None of these statements convince me that http sites should be default flagged as insecure. Take this site, for instance: http://wilsonminesco.com/6502primer/65tutor_intro.html . It is a great resource, but is not available over https. yeah, it's possible that someone could MITM it to provide me with incorrect info on the 6502, but I don't see the disregard for my privacy. I'm never going to put in any of my own info…
Blocking HTTP sites is a bit too far, but an insecure warning is perfectly reasonable as, let's be honest, it is not secure.
For a lot of people, a big scary warning page that says that a page is insecure is essentially a block. Yeah, you can still access it, but a lot fewer people will.
> let's be honest, it is not secure.
My original post is asking for an explanation of how it isn't secure. I would totally understand a browser warning if a user tries to submit a form over http, but for a page like the one I linked I don't see how it can adversely affect the user.
Re: Google and HTTP
#37This also applies to AMP. Its bad enough they have so much control of the web based on how the rank pages in search results, but there is not much we can do about that.
Re: Google and HTTP
#38Just weird and a bad blog post. The author also wrote this: http://scripting.com/2018/02/23.html The owner is a domain parker and is upset that he has to update hundreds of sites in order to be marked as insecure, is what I can gather In the last few weeks he's also wrote: - http://scripting.com/2018/02/21.html - http://this.how/googleAndHttp/ - http://scripting.com/2018/02/08.html
His arguments are also legitimately absurd. He says "if Google succeeds, it will make a lot of the web's history inaccessible", which is patently false given the fact you can always still access HTTP websites , not to mention that services like archive.org and Google's own cache exist. He then makes the argument that HTTPS will make it such that only "super nerds" will be able to create websites. But right now I can…
I think you arguments are absurd. May be give it somethought before lashing out? And what does "legitimately absurd" mean anyway?
>But right now I can host my own blog on services like Netlify...
Again, if you have given it somethought, you might have noticed that the author is talking about old, in-frequently maintained content that was created decades before, and the authors have moved on...
So again, next time, give it some thought before crying "LEGITIAMATLEY ABSURD!!!"
Re: Google and HTTP
#39Earlier quoted context omitted.
His arguments are also legitimately absurd. He says "if Google succeeds, it will make a lot of the web's history inaccessible", which is patently false given the fact you can always still access HTTP websites , not to mention that services like archive.org and Google's own cache exist. He then makes the argument that HTTPS will make it such that only "super nerds" will be able to create websites. But right now I can…
I'm really surprised that this person is a software developer. I'm even more surprised that he still believes this stuff after working for 24 years. I'm really surprised that you think everyone has/should have(?) the same beliefs about such things. He then argues that Google labeling HTTP as not secure is the first step down a path which leads to "blocking the pages outright", which is a prime example of the slippery…
I can install whatever operating system and software I like on almost every single consumer-available computer today. The only prominent "walled garden" is the iPhone, which has < 15% market share. And frankly, I don't mind Apple's iOS. I certainly don't mind the fact that I know that any kernel space software that runs on my phone is cryptographically signed by a trusted party in a chain from the bootloader.
Re: Google and HTTP
#40There really is no absolute right or wrong to this issue. HTTPS is indeed more secure for users, but it does have some cost, and I think OP has a sensible argument. If you really think HTTPS is the best thing ever and is absolutely better than HTTP in every sense, you're just looking at it superficially. When you start looking into how the entire Internet works and what role each party plays in the ecosystem, and how…
However, the whole dns system is centralized. Any alertanative dns root is kinda ignored as well. Its kinda sad.
Also there only a handful of browsers. Even less browser engines. This is also sad, and partly to blame is how complicated the standards are these days.