Earlier quoted context omitted.
Yup, very secure. Then every single IT department installs a cert on the machines to MITM everything.
I have no idea what you're trying to say, there's no IT department managing my laptop and none of the IT departments I've worked in or with "MITM everything." Do you want to try again?
What Is Date:Italy?
31–40 of 69 posts
Re: What Is Date:Italy?
#32Please use HTTPS. I use HTTPS only. I don't think HTTP is acceptable for anyone let alone a technical blog post. It takes a few minutes, and it prevents me and all your visitors from getting all kinds of MITM injections. Thanks.
Man I really hope this doesn't get autoflagged because people need to see that this is an opinion people actually have, and what the (justified) reaction to it is. HTTPS on a blog does nothing. It doesn't protect you from anything. I guarantee you're not getting "all kinds of MITM injections" on this block of text. The only reasonable desire I can think of for "HTTPS everywhere" is hiding the content from your ISP bu…
You actually can’t guarantee anything of the sort. BGP hijacks are real.
Re: What Is Date:Italy?
#33Please use HTTPS. I use HTTPS only. I don't think HTTP is acceptable for anyone let alone a technical blog post. It takes a few minutes, and it prevents me and all your visitors from getting all kinds of MITM injections. Thanks.
MITM attack on a read-only text webpage... okay. More annoying is the slightly shiny/shaded text that is supposed to highlight something. Who chose this style palette?
Millions of routers are compromised. BGP attacks happen. Anything http stands out as an interesting target for injection.
This position is foolish. It’s not a major ask to enable https.
Re: What Is Date:Italy?
#34Earlier quoted context omitted.
Without HTTPS someone could alter the content, spread false information, inject ads, malware, and other stuff, redirect to some other site, … (This is a general remark, but it goes for a blog post like this as well.)
It's still a weak argument since it's extremely rare in practice that's why I suggested blaming the ISP instead since ISP's are the ones that have historically tampered with http content.
Re: What Is Date:Italy?
#35Earlier quoted context omitted.
I have no idea what you're trying to say, there's no IT department managing my laptop and none of the IT departments I've worked in or with "MITM everything." Do you want to try again?
On the flip side, every company I've ever worked for has installed trusted company certs on their computers and do MITM everything.
Re: What Is Date:Italy?
#36Please use HTTPS. I use HTTPS only. I don't think HTTP is acceptable for anyone let alone a technical blog post. It takes a few minutes, and it prevents me and all your visitors from getting all kinds of MITM injections. Thanks.
Surprised this is downvoted. Chrome forces me to click through a warning to even visit HTTP sites nowadays.
Re: What Is Date:Italy?
#37Please use HTTPS. I use HTTPS only. I don't think HTTP is acceptable for anyone let alone a technical blog post. It takes a few minutes, and it prevents me and all your visitors from getting all kinds of MITM injections. Thanks.
Man I really hope this doesn't get autoflagged because people need to see that this is an opinion people actually have, and what the (justified) reaction to it is. HTTPS on a blog does nothing. It doesn't protect you from anything. I guarantee you're not getting "all kinds of MITM injections" on this block of text. The only reasonable desire I can think of for "HTTPS everywhere" is hiding the content from your ISP bu…
That's incorrect, a MitM can only reveal the server hostname by inspecting the SNI during the TLS handshake, but the HTTP request, including the URL and headers, is encrypted.
Re: What Is Date:Italy?
#38Earlier quoted context omitted.
I think you would have a better argument if you said something like: "I don't want my ISP knowing about the content I read" or something along those lines. MITM for a text download is like saying we have to have https for dns (yes DoH exists now), but the point still stands. You aren't sending any sensitive data to the website, MITM is unlikely.
Without HTTPS, every link in the chain between me and your website is a potential attack vector. Maybe I trust my ISP, but do I trust my buddy's cheapo router? What about the shadowy cabal that offers airport wifi? With static webpages, the concern isn't someone snooping in on what I'm reading. It's someone injecting content, probably malware, into the page. Let's say I have a zero-click exploit for Chrome. What can…
Re: What Is Date:Italy?
#39Earlier quoted context omitted.
Surprised this is downvoted. Chrome forces me to click through a warning to even visit HTTP sites nowadays.
It only does that for me if there's an HTTPS option available but it's expired or not configured correctly. Chrome let me right into this site without that warning.
I don't remember turning it on but it's probable that I did, it's not a default yet but will be come October: https://blog.google/security/https-by-defau/
Re: What Is Date:Italy?
#40It’s actually worse than that. It wasn’t always whole coubtries who decided to adopt (or not) but cities and sometimes people within cities (i.e. the protestants in the city would be lagging, or maybe I’m misremembering and this was about people who where abroad) In any case, for awhile, the date you picked depended on who you were writing to. And then also the relative standing. If he was of much lower standing you…
There was some of that indeed, depending on the centralization of the country e.g. Spain and France adopted the gregorian calendar wholesale because the king decreed it, but in less centralised countries like the Dutch Republic or Switzerland it happened by region (the seven catholic cantons switched to the gregorian calendar in 1584, the protestant canton only switched over piece by piece during the 18th century, and Schiers and Grüsch were the last remnants of Julian calendar in the entirety of western europe, only adopting the gregorian calendar in 1812).
... and then there's Sweden, which started on a plan to gradually approach the Gregorian calendar by skipping leap years over 40 years, except they immediately forgot to skip the second and third so concluded the plan was stupid, then instead of switching to gregorian they reverted to julian, before finally switching to gregorian 40 years after that.