Live data from Hacker News

Google Will Soon Shame All Websites That Are Unencrypted

motherboard.vice.com

341–350 of 369 posts

Re: Google Will Soon Shame All Websites That Are Unencrypted

#341

The article title really, really needs an extra word: "Chrome", between "Google" and "Will". At first glance I thought it would be about the search engine, which would be a very disturbing thought indeed; it's already hard enough to find the older, highly informative and friendly sites --- which often are plain HTTP. Nevertheless, quite convincing security arguments aside, I feel this also has a very authoritarian si…

There are already points of centralization at the domain registrar and DNS layers.

That was a major (really the major) basis of the fight against SOPA--it would have required ISPs to interfere with DNS resolution as a way of shutting down serial copyright infringers.

And the U.S. federal government can already seize domain names for some reasons.

So, the question is: does the value of pervasive over-the-wire encryption outweigh the risk additional centralization via CAs? Right now I think it does, but that is in part because I believe that the CA infrastructure itself will improve over time.

Re: Google Will Soon Shame All Websites That Are Unencrypted

#342
post #3

Earlier quoted context omitted.

Sorry?

anyone who does drugs could be a serial killer!! you are not safe to try any other drugs!! here inject these mercuries and aluminumummies!! for your safety we have hidden all posts below the bernie sanders TLS threshold

the downgraded to exploitable crypto for foreign countries

this is for tor, this is for tor servers scattered across the globe

Re: Google Will Soon Shame All Websites That Are Unencrypted

#343
post #256

Earlier quoted context omitted.

Certificates are free. The required competence is only marginally more than the required competence of setting up a website, and is rapidly dropping to zero more. (And is , if your website is hosted by a third-party service, which is a pretty reasonable approach for the organizations you name.) I don't understand what you mean by "Outsourcing security without knowledge is praying for being abused." From your original…

Certificates are free? Some are. Do you trust certificates given without checking the real identity of the user? I do not. It has a cost. If you do not check you have the perfect tool for a MITM. Then is https more expensive than http? Of course you idiot. Have you never seen your CPU burn under https? With TLS the load is on the first connection. Meaning it is around x% (x said to be 1 by google) for long sessions I…

> Certificates are free? Some are. Do you trust certificates given without checking the real identity of the user? I do not. It has a cost. If you do not check you have the perfect tool for a MITM.

But you just said that HTTP was fine, right? You can MITM plaintext HTTP too, so I don't understand why that's a problem for HTTPS to be (potentially) MITMable.

> Of course you idiot.

I have stopped reading here. Please read https://news.ycombinator.com/newsguidelines.html

Re: Google Will Soon Shame All Websites That Are Unencrypted

#344

The article title really, really needs an extra word: "Chrome", between "Google" and "Will". At first glance I thought it would be about the search engine, which would be a very disturbing thought indeed; it's already hard enough to find the older, highly informative and friendly sites --- which often are plain HTTP. Nevertheless, quite convincing security arguments aside, I feel this also has a very authoritarian si…

What we really need is opportunistic unauthenticated encryption with key pinning as a fallback between CA-signed https and plain http. Beating mass passive snooping is worthwhile even if MITM is still a risk.

The Fenrir project does something like this. They first establish a encrypted connection and then you can authenticate, or not. The authentication can also be federated.

Its pretty cool, but its not production ready.

The GNUNet has multible layers and do bottum up encryption on the lower levels.

Re: Google Will Soon Shame All Websites That Are Unencrypted

#345
post #88

Earlier quoted context omitted.

>It was mind boggling that mixed content was "insecure" but HTTP was "secure." HTTP is and always has been insecure and should be marked as such. Why is it mind boggling? Content served over HTTP is obviously less sensitive than content served over HTTPS, mixed content breaks HTTPS.

No. Obviously less is wrong. Here is an example: login over HTTP deliberate because the site doesn't support HTTPS is definitely not less sensitive.

How is it so hard to understand that its not just about your information. A attacker can easly put in new elements that insentivise users to put in information, or to help identify him.

Re: Google Will Soon Shame All Websites That Are Unencrypted

#346

Earlier quoted context omitted.

HTTPS assures the integrity of the data transferred is from the origin domain, so it prevents your ISP from injecting additional ads into tour site, which some ISPs like to do [1]. [1]: http://arstechnica.com/tech-policy/2014/09/why-comcasts-java...

That doesn't convince me; it's like saying every Tom, Dick, and Harry should get encrypted phones because Verizon has the capability to tap into conversations. The onus should be on the provider, not the customer.

You dont think that normal user should use encrypted phone sevices? Are you serious?

Re: Google Will Soon Shame All Websites That Are Unencrypted

#347
post #181

Earlier quoted context omitted.

Guess you're right, fair enough. I still don't agree with putting a scarlet letter on these types of sites though.

Nothing short of that will get HTTPS adoption to approach 100%. Many people have commented that it seems odd to complain about broken HTTPS but not about HTTP; I agree with that. As long as browsers show unencrypted HTTP as "neutral" rather than "bad", far too many sites simply won't care. This has been a long and gradual step, but it needs to happen for HTTP to finally go away.

HTTPS is rather more secure than what HTTP is. Because it creates a relative secure tunnel between the client and host. But HTTPS does not mean 100% secure, it's easy to be hacked by MITM or traffic been spied.

I think that getting rid of HTTP should not be shamed in that way. But google is planning on doing this thing.

Just as someone said, MITM attackers can switch google ads to others, and I think this is the reason why Google wants to shame those sites who use Google Ads and not use HTTPS. Google can make an increasing revenue by this act.

And yet HTTP2 is out, will google shame those sites who only support HTTP1.0/HTTP1.1 ? I don't think so. Because this has almost nothing to do with revenue for Google.

Re: Google Will Soon Shame All Websites That Are Unencrypted

#348
post #17

I think 80% of web sites will be labelled as red-unsafe. SSL layer security is good but sometimes a certificate is expensive and not free. Suppose that you have 10 domains and not all of them are for SNS, banks and etc.. At what minimum cost will you purchase a HTTPS certificate?

nada. http://letsencrypt.org/

letencrypt is in beta testing for now. And they did not claim whether they were going to make this service free forever.

I tried letencrypt, and it works like a charm. But the sad thing is that it needs you to update every 3 months at least for now. And they may have auto-updating script for this, but it is not supported well. Currently the scripts only work for Apache HTTP servers, rather Nginx ones (will work in the future) . I update certificates every 2 months by hands...

Re: Google Will Soon Shame All Websites That Are Unencrypted

#349
post #214
post #76

Earlier quoted context omitted.

Similarly, Google claimed they would start penalizing websites that showed full-page ads for mobile apps instead of showing you the website. But every single time I try to get to Gmail, or Drive, or Calendar, or any Google service on the web using a mobile device, I'm shown a full page ad for a mobile app. Google has been doing this for years, and it seems like it's also been a year since they said they'd punish all…

They also sell full page ads now: https://support.google.com/adxseller/answer/6068103?hl=en

You are right. I think Google want people to get annoyed with this vignette ads if he or she uses google calendar. The user should install Google calendar the APP to be fully controlled by google. Then Google can just sends the user any ad what google like...

They all prefer user using apps rather than web pages. Google and others want to get fully control of users and make money...

Re: Google Will Soon Shame All Websites That Are Unencrypted

#350
post #76

Earlier quoted context omitted.

Similarly, Google claimed they would start penalizing websites that showed full-page ads for mobile apps instead of showing you the website. But every single time I try to get to Gmail, or Drive, or Calendar, or any Google service on the web using a mobile device, I'm shown a full page ad for a mobile app. Google has been doing this for years, and it seems like it's also been a year since they said they'd punish all…

> First results for searching 'calendar': http://i.imgur.com/l3A5Wlh.png Well in your screenshot it seems like you scrolled down on the "calendar" search results. I get some other random thing ahead of Google Calendar, in incognito or not. It is really annoying (I too hate those things, I would have installed the app if I wanted the app), but the click through thing only happens once in my testing. Are you clearing y…

How about using a software to get rid of google ads?

I can erase google ads from DNS level. Users can never reach any google ad at all.

What you think?

Post reply on HN