Live data from Hacker News

Google Will Soon Shame All Websites That Are Unencrypted

motherboard.vice.com

321–330 of 369 posts

Re: Google Will Soon Shame All Websites That Are Unencrypted

#321
post #244

Earlier quoted context omitted.

Not all countries have feminine gender, just check https://en.wikipedia.org/wiki/Fatherland

I never thought about the question of whether, in languages that require nouns to have grammatical gender, particular countries may have a different grammatical gender from others, but on reflection I already know examples where they do in Portuguese: o Brasil, o Canadá (amusing to me because of the national anthem), but a Argentina, a Alemanha. I wonder if this also happens in German; the only examples I'm thinking…

Several countries have articles in German, most don't. Plural countries (USA, UAE) have the plural article, which in the standard form is the same as the feminine article ("die") which makes for even more confusion, but when used in a case changes differently ("in den USA" vs "in der Schweiz") :)

Some feminine countries: Switzerland, the Dominican Republic, Mongolia, Slovakia, Turkey, Ukraine, Central African Republic.

Male, in addition to your own list: Niger (!= Nigeria), Sudan, Vatican.

Neutral: UK (because kingdom is a neutral noun in German), potentially others

Re: Google Will Soon Shame All Websites That Are Unencrypted

#322
post #76
post #64

Which is hilarious because the reason I can't switch The New Yorker website to HTTPS is because of ads - which I'm getting from Google DFP which allows non-secure ad assets. In short; Google will penalize me because I use Google. The universe has a sense of humor.

Similarly, Google claimed they would start penalizing websites that showed full-page ads for mobile apps instead of showing you the website. But every single time I try to get to Gmail, or Drive, or Calendar, or any Google service on the web using a mobile device, I'm shown a full page ad for a mobile app. Google has been doing this for years, and it seems like it's also been a year since they said they'd punish all…

They also said not to "penalize" websites based on user agent. Yet they do it and have been doing it for years.

They also said to use valid html/etc while they didn't do it for cost saving/performance reasons. Not sure this one is still true.

My guess is that this list of preaching water and drinking wine is pretty long for Google. I think their view is they know what they are breaking so it is OK in that particular case. The rest of us has to suck it up.

Re: Google Will Soon Shame All Websites That Are Unencrypted

#323

Earlier quoted context omitted.

If they don't bother why should people bother to pay for their hosting? There are many, many hosting companies that do bother and I am using one of them. Had no problem installing Let's Encrypt cert on shared hosting via cPanel there.

Who are you using?

I am using ASO.

Re: Google Will Soon Shame All Websites That Are Unencrypted

#324

Earlier quoted context omitted.

> I do have the app. And that fact makes this double-annoying. It really just shows the sad state of mobile advertising when they're showing you ads for an app you already have.

Sad state? How do you expecet them to know all the apps installed on your phone? And if they DID know this information, people would be up in arms about privacy or lack there-of.

Yes, showing you an advertisement for an app you've already installed is bad UI/UX, regardless of the reason why. On the publisher side, it's also a wasted ad impression.

I don't expect them to know all the apps installed on my phone, nor do I think they need that much information to solve this particular problem.

Re: Google Will Soon Shame All Websites That Are Unencrypted

#325

Earlier quoted context omitted.

Getting a Google domain means giving up getting new features from Google :( (pauses to clean up bitterness)

No, it does not. Signing up for google apps and choosing to use the google apps account as your primary google user account causes you to get new features on a delayed schedule. You can get a domain through google without switching your google identity to it. You can also sign up for google apps on a non-google domain. google domains and google apps are not the same thing.

On Google Apps there are features that have been deployed years ago for regular accounts and that are still not available for Google Apps customers.

The one feature missing and that was painful for me were Contacts photos with a resolution higher than 96x96 pixels. On a latest generation Android with good resolution it sucks and I would have preferred if Contacts photos weren't synchronized at all. I ended up switching to a CardDAV provider and in the end I gave up on Google Apps for other reasons as well. And for the record, Google accounts had this resolution increased in 2012 ;-)

Re: Google Will Soon Shame All Websites That Are Unencrypted

#326

Earlier quoted context omitted.

> I do have the app. And that fact makes this double-annoying. It really just shows the sad state of mobile advertising when they're showing you ads for an app you already have.

On the other hand, I like that websites are unable to query my phone to find out what apps I have installed.

Yes I agree with you, I don't want any random website to be able to query my phone to find out what apps I have installed either.

However, if I'm on a specific app publisher's website, I wouldn't mind letting them know (through some mechanism) that I've already installed their specific app.

Re: Google Will Soon Shame All Websites That Are Unencrypted

#327
post #76

Earlier quoted context omitted.

Similarly, Google claimed they would start penalizing websites that showed full-page ads for mobile apps instead of showing you the website. But every single time I try to get to Gmail, or Drive, or Calendar, or any Google service on the web using a mobile device, I'm shown a full page ad for a mobile app. Google has been doing this for years, and it seems like it's also been a year since they said they'd punish all…

No offense meant but why not get the app? I understand not wanting an application for a news website or something like that but something you use often like google calendar it would seem like the application would be better than the mobile page.

Not if you want to allow attendees to edit your event.

This is missing from the android app. So you have to browse to the calendar on the web and ... this.

Re: Google Will Soon Shame All Websites That Are Unencrypted

#328
I feel a bit of dissonance on hn on the issue of https. On issues of surveillance and spying the responses are often measured and there is generally a balanced debate, and yet on ssl suddenly its a matter of extreme urgency with strident positions backed up by references to mitm, spying and isp injected ads.

This is not as urgent a matter as some here tend to make it, better to resolve it properly than rush into half baked solutions like Google shaming websites. Why should a private company have the ability to shame websites and drive decisions a certain direction without any consultative process and accountability. Surely these are decisions for industry groups and wide consensus, and not individual corporates driven by self interest.

Corporates routinely mitm ssl traffic and no one is shaming them or the equipment makers for that, so ssl and mitm is hardly going to be problem for state actors. For protection against less influential actors, banks and those who process sensitive data have been on https for a long time now so where is this urgency and the need to take action coming from?

Everyone agrees security is good but the mechanism to enable this cannot be given up to browser makers and CAs. This is a complete loss of end user control and a significant step back from the open net that cannot just be brushed aside.

Not everyone needs https and for ads injections the pressure should be on ISPs to stop the illegal behavior. Why can't we shame ISPs instead of forcing all websites to https?

Other solutions like signing content that empowers individuals rather than corporates and vested interests should be explored. The same browser makers went ahead and arbitrarily started flashing grave warnings on self signed certs without any consultative process or accountability.

Re: Google Will Soon Shame All Websites That Are Unencrypted

#329
post #48
post #17

Earlier quoted context omitted.

nada. http://letsencrypt.org/

Most shared hosting accounts charge extra for a dedicated IP address, both for setup and on a monthly basis. Don't underestimate how many blogs, churches, small businesses, etc still use services like that. To be fair, many of those sites probably ARE insecure, but it seems to be a little bit overkill to "shame" them for not implementing encryption.

nginx + TLS, and TLS is many-certs-same-IP friendly from the start.

SSL is insecure already anyway.

Re: Google Will Soon Shame All Websites That Are Unencrypted

#330
post #290

The article title really, really needs an extra word: "Chrome", between "Google" and "Will". At first glance I thought it would be about the search engine, which would be a very disturbing thought indeed; it's already hard enough to find the older, highly informative and friendly sites --- which often are plain HTTP. Nevertheless, quite convincing security arguments aside, I feel this also has a very authoritarian si…

Repressive governments somehow convincing all CAs worldwide to refuse to issue certificates for your domain is a pretty distant hypothetical. Repressive governments monitoring and altering unencrypted communications in very sophisticated ways is a reality today. It's not a freedom/security tradeoff but a freedom/freedom tradeoff. Not to mention that, of course, access to most websites is already gated by a central gr…

Repressive governments monitoring and altering unencrypted communications in very sophisticated ways is a reality today

They could easily alter encrypted communications to effectively censor too, thanks to the all-or-nothing nature of encryption with authentication. Because by design, the certificate is presented in cleartext, it would be pretty easy to blacklist CAs and then cut off the connection if one of those is detected. Alternatively, whitelist CA(s) [1]. Analysing plaintext takes more computational resources, especially if things like steganography are used.

[1] Related article: https://news.ycombinator.com/item?id=10663843

Post reply on HN