This is the kind of sunset you love to see. Retirement because they succeeded and therefore became redundant, rather than due to failure. If there's one organization I love to see succeed, it's the EFF.
That’s how I used to feel until I found out they accepted millions in donations from companies like Google and Facebook/their executives/their executives’ charities. I’m just some guy on the Internet but IMHO their being OK with massive conflicts of interest means I no longer trust them.
HTTPS Everywhere will sunset in January 2023
51–60 of 148 posts
Re: HTTPS Everywhere will sunset in January 2023
#52Earlier quoted context omitted.
It's like wearing a bulky level 3 bullet proof vest while you're at home cooking dinner. Yeah, it's keeping you safer. There's no doubt about that. The real dangers on the web come from the insane behavior of running all arbitrary code sent to the browser from anywhere. Like opening every email attachment you get sent. NoScript temp whitelist only provides a lot more safety than HTTPS Everywhere and doesn't give all…
You need HTTPS to even begin trusting remote code. For instance, you download uMatrix to setup a whitelist. Where did uMatrix come from? If you downloaded it over HTTP, then you could be running anything. Even if you have a checksum for uMatrix, you can't trust it if you got the checksum over HTTP. Now let's say you installed uMatrix and you want to trust a script. Well, how do you know that the script you downloaded…
But is uMatrix to trust?
Can you trust uMatrix developers?
I have bought a pair of shoes from an HTTPS only web sites, shoes never arrived, HTTPS apparently can't fix everything.
Trusting trust is a problem since computing was invented. [1]
[1] WARNING! PDF! https://www.cs.cmu.edu/~rdriley/487/papers/Thompson_1984_Ref...
Re: HTTPS Everywhere will sunset in January 2023
#53This is the kind of sunset you love to see. Retirement because they succeeded and therefore became redundant, rather than due to failure. If there's one organization I love to see succeed, it's the EFF.
There's still a real issue with infrastructre that has web configuration. Everything from home routers to video cameras and so on. Not being able to ship with a certificate that passes browser security checks is a problem that essentially nobody has addressed.
When people connect to an IOT device, they need to be able to connect with a web browser and not jump through hoops to say, "No, really I know that this is a secure connection." Because we can't keep teaching people to dodge secure connections when they should care about having secure connectinos. As much as I don't like IOT, but this is an issue that needs to be easier than "understand cyrptography configuration, generate your own keys, and install them wherever you need them".
That's all besides the vendor "solution" of "install this phone app that will maybe barely work except for the parts that track your data forever LOL thx sucker".
Re: HTTPS Everywhere will sunset in January 2023
#54HTTPS Everywhere being available in browsers as an option is great. HTTPS Everywhere being promoted as something you should have on by default is bad. HTTPS, like much else, relies on incorporated entities as certificate authorities. And that's fine for commercial interactions and if browsers were only for interacting with businesses. But by a combination of centralization in a few CAs (everyone uses LetsEncrypt now)…
Especially around security where techies have a tendency to shut down their brains whenever it is brought up, as if in the name of security everything else should be compromised.
Re: HTTPS Everywhere will sunset in January 2023
#55Earlier quoted context omitted.
HTTP is not ok. Anyone can ready / modify what is being sent. This privacy intrusion will definitely happen, whereas the risk of being banned by "some external corporation" is low. And, you always have the option of self-signing your own certificate, which is at least as secure as using HTTP, and much more secure if you can verify the certificate via a side channel.
> HTTP is not ok actually, it is. HTTP is perfectly fine. [1] > Anyone can ready / modify what is being sent Anyone can break a window and enter my house. But I haven't aired a private army to patroll the windows. NSA can break HTTPS, TGF exists and China Trusted SSL Certificates are a thing. False sense of security is often more dangerous than a real sense of insecurity. Edit: [1] how many of you don't terminate SSL…
Re: HTTPS Everywhere will sunset in January 2023
#56This is the kind of sunset you love to see. Retirement because they succeeded and therefore became redundant, rather than due to failure. If there's one organization I love to see succeed, it's the EFF.
Eh, kind of. It's successful as far as the Internet, which is great. But Internet web pages isn't everything. There's still a real issue with infrastructre that has web configuration. Everything from home routers to video cameras and so on. Not being able to ship with a certificate that passes browser security checks is a problem that essentially nobody has addressed. When people connect to an IOT device, they need t…
Re: HTTPS Everywhere will sunset in January 2023
#57Earlier quoted context omitted.
> HTTP is not ok actually, it is. HTTP is perfectly fine. [1] > Anyone can ready / modify what is being sent Anyone can break a window and enter my house. But I haven't aired a private army to patroll the windows. NSA can break HTTPS, TGF exists and China Trusted SSL Certificates are a thing. False sense of security is often more dangerous than a real sense of insecurity. Edit: [1] how many of you don't terminate SSL…
So because the government can potentially decrypt your traffic, you don't care if anyone can? Do you use online banking? Do you care if you transmit your password to your bank account in plaintext? What if you need to call your bank? Would you really trust a phone number delivered over HTTP? That just seems crazy to me.
that's a very bald assumption, my dear friend.
But in practice, yes, it is safe do not care of the possibility that someone is going to inject a script in your blog header, because I am no police officer, I do not work overtime, fighting crime. [1]
Same way I'm not worried that someone is going to steal my car and use it to rob a bank or worse.
> Do you use online banking?
Banks also have guards at the doors.
They handle other people's money, of course they care about it and about the safety of their employees.
Are you a bank?
> Do you care if you transmit your password to your bank account in plaintext?
Not really.
99% of my passwords are passw0rd on websites I really don't care about.
It is much harder, if not impossible, to guess my username.
I bet I am not the only one.
Besides, my bank ask me to confirm any operation in a MFA way.
If they notice something strange, they call me, on my phone, a human calls me.
It's their job.
> Would you really trust a phone number delivered over HTTP?
I've trusted for the majority of my life phone numbers sent unencrypted through wires that everybody could wiretap to and then by email...
Nothing bad ever happened.
Besides, what can happen if you call the wrong number?
I do not believe that the Grudge is a real story.
The point is: no, I am not paranoid.
Common sense is enough 99% of the times.
Re: HTTPS Everywhere will sunset in January 2023
#58This is the kind of sunset you love to see. Retirement because they succeeded and therefore became redundant, rather than due to failure. If there's one organization I love to see succeed, it's the EFF.
Eh, kind of. It's successful as far as the Internet, which is great. But Internet web pages isn't everything. There's still a real issue with infrastructre that has web configuration. Everything from home routers to video cameras and so on. Not being able to ship with a certificate that passes browser security checks is a problem that essentially nobody has addressed. When people connect to an IOT device, they need t…
HTTPS Everywhere was "this site already has HTTPS, and really should only use that, but doesn't, so we'll redirect you to the HTTPS version". Now sites that have HTTPS default to it, and browsers have options to basically try https first and see if it works.
Re: HTTPS Everywhere will sunset in January 2023
#59Earlier quoted context omitted.
Eh, kind of. It's successful as far as the Internet, which is great. But Internet web pages isn't everything. There's still a real issue with infrastructre that has web configuration. Everything from home routers to video cameras and so on. Not being able to ship with a certificate that passes browser security checks is a problem that essentially nobody has addressed. When people connect to an IOT device, they need t…
Couldn't browsers just designate the .local tld to not check for SSL certs and enforce that it resolves to an IP on the current network? Seems like a simple solution for this.
Re: HTTPS Everywhere will sunset in January 2023
#60Earlier quoted context omitted.
Couldn't browsers just designate the .local tld to not check for SSL certs and enforce that it resolves to an IP on the current network? Seems like a simple solution for this.
How do we define 'current network'?
It's also something that can be done with a level of reliability that will impress incredulous people. But that there will always be somebody to complain that is not following the standard recommendations.