Live data from Hacker News

Encrypted web traffic now exceeds 90%

netmarketshare.com

71–80 of 311 posts

Re: Encrypted web traffic now exceeds 90%

#71

Awesome! Any idea how much of that is attributable to LetsEncrypt and HTTPSEverywhere?

I'd imagine that a lot of this is attributable to Firesheep calling attention to how anyone on a public Wi-Fi network could snoop on your Facebook traffic.

Most of the major websites fast-tracked HTTPS shortly after that.

Re: Encrypted web traffic now exceeds 90%

#72
post #67

I don't know why so many people here are patting themselves on the back over this. This is not the kind of encryption people were talking about in the 90s and 00s. A lot of this encryption is not point-to-point. It merely secures user's interaction with some middleman (or their server). What would the numbers be if you subtracted all the traffic that can be snooped on by Google, Amazon and Cloudflare?

The encryption is still point-to-point, just that the website you are connecting to has chosen to make their "point" AWS or Cloudflare or whatever else. You could as easily host something in your own DC or from a machine under your desk.

Re: Encrypted web traffic now exceeds 90%

#73
We often hear the complaint here that nobody cares / cared about Snowden's revelations. But to me it seems he did provide a lot of the impetus for having HTTPS virtually everywhere and a lot of the instant messenging apps being end-to-end encrypted. Most of WhatsApp's users are as non-technical as it gets, and yet they use the kind of encryption that only computer enthusiasts were interested in just a couple years ago. It's a great development (all the limitations and caveats notwithstanding) IMO.

Re: Encrypted web traffic now exceeds 90%

#75
post #5

Good news for sure, but note that this isn't a total Internet scan: > We collect data from the browsers of site visitors to our exclusive on-demand network of analytics and social bookmarking products. More details about their samples: https://netmarketshare.com/methodology I would be more inclined to trust sources like https://transparencyreport.google.com/https/overview and Firefox Telemetry which come directly fro…

> from mobile apps (most of which have to be encrypted now I think) Since the end of 2016 on iOS and since Android v9, apps have to communicate over HTTPS. I guess you can technically visit HTTP sites via a browser, but I'd bet that >90% of the traffic from smartphones is over HTTPS.

Do iOS or Android have any requirements vis a vis HSTS or HPKP?

Re: Encrypted web traffic now exceeds 90%

#76
post #67

I don't know why so many people here are patting themselves on the back over this. This is not the kind of encryption people were talking about in the 90s and 00s. A lot of this encryption is not point-to-point. It merely secures user's interaction with some middleman (or their server). What would the numbers be if you subtracted all the traffic that can be snooped on by Google, Amazon and Cloudflare?

What are you talking about about? I think you better look up how https/tls works??? Sure you have to trust the certificate authority. Also can you imagine the scandal that would erupt if Google or AWS cloud was discovered to be eavesdropping on companies running things in their cloud? I don't think so.

Re: Encrypted web traffic now exceeds 90%

#77
post #67

I don't know why so many people here are patting themselves on the back over this. This is not the kind of encryption people were talking about in the 90s and 00s. A lot of this encryption is not point-to-point. It merely secures user's interaction with some middleman (or their server). What would the numbers be if you subtracted all the traffic that can be snooped on by Google, Amazon and Cloudflare?

You're not wrong, but the realistic alternative is having it the same way, just without any encryption.

Re: Encrypted web traffic now exceeds 90%

#78
post #60

While this milestone is wonderful, don't forget that it can't be decrypted for now . IMO we trust contemporary encryption algorithms too much, putting too much data through the wires that will only increase in value. We aren't at the end of the evolution either: we still don't have really secure random generators everywhere, we are still using key exchange methods that aren't quantum proof. And of course, computer pr…

Encryption is worthless without properly enforcing it. How easy is it to trick your victim's bank into granting you access with a SIM swap? We need 2FA everywhere and stop relying on SMS for authentication.

It's not worthless. It shrinks the attack surface and makes attacks more costly to execute. There's always an arms race though :P

Re: Encrypted web traffic now exceeds 90%

#80
post #67

I don't know why so many people here are patting themselves on the back over this. This is not the kind of encryption people were talking about in the 90s and 00s. A lot of this encryption is not point-to-point. It merely secures user's interaction with some middleman (or their server). What would the numbers be if you subtracted all the traffic that can be snooped on by Google, Amazon and Cloudflare?

What are you talking about about? I think you better look up how https/tls works??? Sure you have to trust the certificate authority. Also can you imagine the scandal that would erupt if Google or AWS cloud was discovered to be eavesdropping on companies running things in their cloud? I don't think so.

The point is that if you're communicating with someone via Google, encryption terminates at Google, not with the other party.
Post reply on HN