Live data from Hacker News

Google and HTTP

this.how

31–40 of 63 posts

Re: Google and HTTP

#31
post #9

Did he really dismiss the huge benefit of https that my browser is guaranteed to receive the exact content that the site owner sent me, with an idiotic argument that while it prevents Starbucks or Comcast from pwning me, it doesn't prevent the browser. Really?

No. What he said is that Google says that https prevents MITM, but never mentions that they will still be able to do it. I don't see a dismissal, just a criticism of Google.

Re: Google and HTTP

#32
post #9

Did he really dismiss the huge benefit of https that my browser is guaranteed to receive the exact content that the site owner sent me, with an idiotic argument that while it prevents Starbucks or Comcast from pwning me, it doesn't prevent the browser. Really?

How many fiascos with CAs do you need, not to mention protocol issues, to stop believing in HTTPS guarantees?

Re: Google and HTTP

#33

Earlier quoted context omitted.

That's what I was referring to. I don't understand what you don't understand about the reference.

Displaying a warning to users doesn't make sites "inaccessible".

It makes it practically inaccessible if the target audience of the page are not savvy enough to go past the warning and access the content. Most of the people ll be scared away by the warning..and that is the whole point...

Re: Google and HTTP

#34
post #28

Earlier quoted context omitted.

I was referring specifically to the author's claim that deprecating HTTP and displaying a warning to users is the equivalent of "rendering large parts of the web inaccessible" and "massive book burning".

If you mark something as 'Not Secure' you're effectively telling users not to access it. It doesn't matter in practice if the content is still accessible when the browser tells people that accessing it is dangerous. A lot of content that exists on the unmaintained web is going to effectively be lost, and maybe that's okay because the benefits are worth it, but that's the argument that needs to be made.

> It doesn't matter in practice if the content is still accessible when the browser tells people that accessing it is dangerous.

It certainly does matter. There's a fundamental different between people being discouraged from accessing a website, and said website being completely inaccessible.

Re: Google and HTTP

#35
post #28

Earlier quoted context omitted.

I was referring specifically to the author's claim that deprecating HTTP and displaying a warning to users is the equivalent of "rendering large parts of the web inaccessible" and "massive book burning".

If you mark something as 'Not Secure' you're effectively telling users not to access it. It doesn't matter in practice if the content is still accessible when the browser tells people that accessing it is dangerous. A lot of content that exists on the unmaintained web is going to effectively be lost, and maybe that's okay because the benefits are worth it, but that's the argument that needs to be made.

A lot of content which exists on the unmaintained web is going to be lost anyway, regardless of HTTP. Hosting sites shut down after a while. There's a ton of content that was on Geocities, for example, which is now inaccessible.

A migration of newer websites to HTTPS is no more a loss to data than deprecating old versions of HTML in newer versions of Chrome or upgrading newer servers to HTTP/2. The old ones will still exist. And if they cease to exist, it's almost certainly not going to be because a browser displays a "not secure" warning on the top left corner of the scene.

There are also entire websites and communities built upon the archival of data:

https://www.archiveteam.org/index.php?title=Main_Page

https://archive.org

Re: Google and HTTP

#36
post #25

Earlier quoted context omitted.

None of these statements convince me that http sites should be default flagged as insecure. Take this site, for instance: http://wilsonminesco.com/6502primer/65tutor_intro.html . It is a great resource, but is not available over https. yeah, it's possible that someone could MITM it to provide me with incorrect info on the 6502, but I don't see the disregard for my privacy. I'm never going to put in any of my own info…

Blocking HTTP sites is a bit too far, but an insecure warning is perfectly reasonable as, let's be honest, it is not secure.

I edited my post before your response to change it to "flagged," but failed to call out the change initially. Sorry, it's fixed now.

For a lot of people, a big scary warning page that says that a page is insecure is essentially a block. Yeah, you can still access it, but a lot fewer people will.

> let's be honest, it is not secure.

My original post is asking for an explanation of how it isn't secure. I would totally understand a browser warning if a user tries to submit a form over http, but for a page like the one I linked I don't see how it can adversely affect the user.

Re: Google and HTTP

#37
Maybe everyone should use HTTPS, or maybe it's a bad idea. But Google shouldn't unilaterally decide what is good for the rest of us. I'm with the author on that.

This also applies to AMP. Its bad enough they have so much control of the web based on how the rank pages in search results, but there is not much we can do about that.

Re: Google and HTTP

#38
post #14

Just weird and a bad blog post. The author also wrote this: http://scripting.com/2018/02/23.html The owner is a domain parker and is upset that he has to update hundreds of sites in order to be marked as insecure, is what I can gather In the last few weeks he's also wrote: - http://scripting.com/2018/02/21.html - http://this.how/googleAndHttp/ - http://scripting.com/2018/02/08.html

His arguments are also legitimately absurd. He says "if Google succeeds, it will make a lot of the web's history inaccessible", which is patently false given the fact you can always still access HTTP websites , not to mention that services like archive.org and Google's own cache exist. He then makes the argument that HTTPS will make it such that only "super nerds" will be able to create websites. But right now I can…

>His arguments are also legitimately absurd...

I think you arguments are absurd. May be give it somethought before lashing out? And what does "legitimately absurd" mean anyway?

>But right now I can host my own blog on services like Netlify...

Again, if you have given it somethought, you might have noticed that the author is talking about old, in-frequently maintained content that was created decades before, and the authors have moved on...

So again, next time, give it some thought before crying "LEGITIAMATLEY ABSURD!!!"

Re: Google and HTTP

#39

Earlier quoted context omitted.

His arguments are also legitimately absurd. He says "if Google succeeds, it will make a lot of the web's history inaccessible", which is patently false given the fact you can always still access HTTP websites , not to mention that services like archive.org and Google's own cache exist. He then makes the argument that HTTPS will make it such that only "super nerds" will be able to create websites. But right now I can…

I'm really surprised that this person is a software developer. I'm even more surprised that he still believes this stuff after working for 24 years. I'm really surprised that you think everyone has/should have(?) the same beliefs about such things. He then argues that Google labeling HTTP as not secure is the first step down a path which leads to "blocking the pages outright", which is a prime example of the slippery…

> 20 years ago people thought buying computers on which you can't install software some central authority didn't approve of was preposterous, and yet here we are today with walled gardens and the like.

I can install whatever operating system and software I like on almost every single consumer-available computer today. The only prominent "walled garden" is the iPhone, which has < 15% market share. And frankly, I don't mind Apple's iOS. I certainly don't mind the fact that I know that any kernel space software that runs on my phone is cryptographically signed by a trusted party in a chain from the bootloader.

Re: Google and HTTP

#40

There really is no absolute right or wrong to this issue. HTTPS is indeed more secure for users, but it does have some cost, and I think OP has a sensible argument. If you really think HTTPS is the best thing ever and is absolutely better than HTTP in every sense, you're just looking at it superficially. When you start looking into how the entire Internet works and what role each party plays in the ecosystem, and how…

I can agree that CA are a point of centralization. A web of trust in my opinion is better such as used in PGP.

However, the whole dns system is centralized. Any alertanative dns root is kinda ignored as well. Its kinda sad.

Also there only a handful of browsers. Even less browser engines. This is also sad, and partly to blame is how complicated the standards are these days.

Post reply on HN