Live data from Hacker News

The Bureau of Meteorology website does not support connections via HTTPS

bom.gov.au

41–50 of 58 posts

Re: The Bureau of Meteorology website does not support connections via HTTPS

#41

Earlier quoted context omitted.

Nah, the NZ secret police is too busy removing NZ from maps so no one can find us.

I feel like all police in NZ are secret police because I never see any out in the street anymore.

Now you mention it, I only really see police cars around here - quite rare to see police walking.

I guess this is an effect of having built a digital panopticon. As pretty much everything we do leaves a digital trace and as one is oblivious to being observed (with observation potentially occurring in the future as automated agents run over data) the potential scrutiny changes behaviour. And that in turn allows for a decrease the number of police required to be physically present.

Re: The Bureau of Meteorology website does not support connections via HTTPS

#42
post #12
post #7

Earlier quoted context omitted.

It's just dangerous because any party on the way between wifi and the server can edit the content See: why are free proxies free https://blog.haschek.at/2013/05/why-free-proxies-are-free-js...

In the same way as walking to the bank is dangerous because any party on the way can rob you on the way? I regularly visit: www.bom.gov.au/ /forecasts/ .shtml It either shows me the forecast or it doesn't. To date it's always worked - if one day it doesn't I might have to look out of a window.

Imagine a major weather event is coming and a warning banner shows on the weather site telling you to stay off the roads. But some carelessly injected ad covers it, or the injected CSS makes it unreadable. You don't see it and suffer a crash.

Government communications should not be subjected to arbitrary modification by intermediaries. Ad injection on HTTP is (or at least was, when unencrypted HTTP was popular) common. It also raises the concern that the ad will appear to have government sponsorship, which invites scams and other malvertising.

A government agency should seek to communicate information with the public, especially safety information, via an untamperable communication channel.

Re: The Bureau of Meteorology website does not support connections via HTTPS

#44
post #12
post #7

Earlier quoted context omitted.

It's just dangerous because any party on the way between wifi and the server can edit the content See: why are free proxies free https://blog.haschek.at/2013/05/why-free-proxies-are-free-js...

In the same way as walking to the bank is dangerous because any party on the way can rob you on the way? I regularly visit: www.bom.gov.au/ /forecasts/ .shtml It either shows me the forecast or it doesn't. To date it's always worked - if one day it doesn't I might have to look out of a window.

> In the same way as walking to the bank is dangerous

It could be if anyone could make their shop look exactly like a real bank branch.

Re: The Bureau of Meteorology website does not support connections via HTTPS

#45

HTTPS is still a pain in the ass, even in 2024. If letsencrypt would offer wildcard certificates with their url based authentification as they offer for non-wildcard certificates, it would be ok. But having to tinker with the DNS infrastructure for each project which wants to use domain wide HTTPS is so much hassle.

What's the challenge for you? Does your DNS server not have an API, is it internal politics and process, or something else?

Re: The Bureau of Meteorology website does not support connections via HTTPS

#46
post #32

Controverse opinion: Why do I need https when looking for the weather forcast. Https is blindly thrown on everything. If the data is public and no login or personal/sensitive data is involved why do I need https?

> If the data is public and no login or personal/sensitive data is involved why do I need https? Do you care about if the data actually comes from your weather forecasting service and was not tampered with by a third party? Then you need https as well. A different example: a podcasts website I've seen was served over http, and someone argued the same (data is public, no login). The page contained an IBAN for donation…

No need for encryted data transfer here. Proven authority would be enough

Re: The Bureau of Meteorology website does not support connections via HTTPS

#47
post #32

Earlier quoted context omitted.

> If the data is public and no login or personal/sensitive data is involved why do I need https? Do you care about if the data actually comes from your weather forecasting service and was not tampered with by a third party? Then you need https as well. A different example: a podcasts website I've seen was served over http, and someone argued the same (data is public, no login). The page contained an IBAN for donation…

No need for encryted data transfer here. Proven authority would be enough

HTTPS is the method by which authority is proven.

Re: The Bureau of Meteorology website does not support connections via HTTPS

#48
post #12

Earlier quoted context omitted.

In the same way as walking to the bank is dangerous because any party on the way can rob you on the way? I regularly visit: www.bom.gov.au/ /forecasts/ .shtml It either shows me the forecast or it doesn't. To date it's always worked - if one day it doesn't I might have to look out of a window.

Imagine a major weather event is coming and a warning banner shows on the weather site telling you to stay off the roads. But some carelessly injected ad covers it, or the injected CSS makes it unreadable. You don't see it and suffer a crash. Government communications should not be subjected to arbitrary modification by intermediaries. Ad injection on HTTP is (or at least was, when unencrypted HTTP was popular) commo…

It's the BoM site, in Australia.

As a site its considerably less authorative than you seem to believe; people get weather warnings here in Australia from the TV, from the radio, from apps on their phones, from looking outside and seeing weather fronts rolling in.

Few people actually directly visit the BoM site, those that do are generally long time users familiar with the site using the usual array of adblockers and noscript, unlikely to fall for "Click here" injection attacks, and more likely to have a direct fibre | line connection to a major ISP to BoM with little chance for malicious injection in any case.

The risks are understood and doomsday scenarios have yet to occur after nearly 40 odd years online as a non https site.

Re: The Bureau of Meteorology website does not support connections via HTTPS

#49

What practical difference does it make if I connect to an Australian weather forecast site via HTTP or HTTPS? Is the NZ secret police gonna MITM a rain forecast my way when it's actually gonna be a very sunny day?

Here's where people from Australian military intelligence sign-in: http://reg.bom.gov.au/defence/

You tell me why http is bad now.

Re: The Bureau of Meteorology website does not support connections via HTTPS

#50

What practical difference does it make if I connect to an Australian weather forecast site via HTTP or HTTPS? Is the NZ secret police gonna MITM a rain forecast my way when it's actually gonna be a very sunny day?

You can sign in to this website. If you do, your password has been sent over clear text. People re-use passwords across sites.
Post reply on HN