Live data from Hacker News

Google Will Soon Shame All Websites That Are Unencrypted

motherboard.vice.com

81–90 of 369 posts

Re: Google Will Soon Shame All Websites That Are Unencrypted

#81

Yes, shame all libraries/swimming pools giving their schedule online without HTTPS. Shame gutenberg project, the documentations for OS, code, your washing machine. Why would money from libraries gutenberg project, NGOs informations go to more expansive OPEX for web hosting when an information is clearly designed and OK to be public? And does not require adds or payment. Google has some godwin point very authoritative…

> Yes, shame all libraries/swimming pools giving their schedule online without HTTPS. Shame gutenberg project, the documentations for OS, code, your washing machine.

So it's OK for someone to tamper with your documentation to trick you into doing something dangerous? Is it OK for a librarian to give out information on who looked at what?

> Basically every fucking internet users pay the 95th percentile transit to google products even if they don't watch videos on youtube, don't use gmail or else.

Except Google does pay for their transit. They pay for bulk transit to go around the world. Just like everyday internet users pay their ISP to get data the rest of the way down the road to where they are.

Re: Google Will Soon Shame All Websites That Are Unencrypted

#82
post #76
post #64

Which is hilarious because the reason I can't switch The New Yorker website to HTTPS is because of ads - which I'm getting from Google DFP which allows non-secure ad assets. In short; Google will penalize me because I use Google. The universe has a sense of humor.

Similarly, Google claimed they would start penalizing websites that showed full-page ads for mobile apps instead of showing you the website. But every single time I try to get to Gmail, or Drive, or Calendar, or any Google service on the web using a mobile device, I'm shown a full page ad for a mobile app. Google has been doing this for years, and it seems like it's also been a year since they said they'd punish all…

Yahoo shows YMail. Bing is the only one shows Gmail as first, although Yahoo technically uses Bing. You can pretty much say Yahoo actually "put herself above others" and more guilty than Google. In fact, I don't think Google is doing anything wrong. After all, Gmail is popular, and if you are doing a Google search, the user may be interested to know Google also offer email and most likely the user is already a Google user.

Re: Google Will Soon Shame All Websites That Are Unencrypted

#83
post #65

Earlier quoted context omitted.

SSH doesn't get this right. It's no better than a (auto-pinned) self-signed cert, in our world. I challenge everyone to find in their extended group of friends and colleagues, and their friends and colleagues, a single person who consistently checks the fingerprint* on every first SSH connection. Id personally have a hard time finding someone who even knows it matters. And if you don't? Mitm can get your password, or…

-o VisualHostKey=yes

A band-aid, I'm afraid.

Without going into the question of how many bits of entropy that actually has when used with human beings in real settings, and just assume it's a perfect check; my question stands: how many people can you find who use this?

Many SSH clients don't even support it, at all. PuTTY and almost anything that uses SSH for tunneling.

When they do: how many of your hosts do you know the image of?

Again: nice idea, but utterly impotent in our universe.

Compare to the efficiency of e.g. WPA2 keys: less theoretically beautiful, but much more efficient with humans.

Re: Google Will Soon Shame All Websites That Are Unencrypted

#84
post #63
post #45

Earlier quoted context omitted.

They are a platinum sponsor of Letsencrypt, so...done?

That doesn't mean anything other than "we like the idea, you convinced us, we have some budget, we will sponsor in some way money and human resource."

Er, isn't that how it'd work internally too?

Re: Google Will Soon Shame All Websites That Are Unencrypted

#85
post #63
post #45

Earlier quoted context omitted.

They are a platinum sponsor of Letsencrypt, so...done?

That doesn't mean anything other than "we like the idea, you convinced us, we have some budget, we will sponsor in some way money and human resource."

If you're interested in more direct support, please star my ticket[1], it's likely that the same functionality would work for the https loadbalancer as well.

[1] https://code.google.com/p/googleappengine/issues/detail?id=1...

Re: Google Will Soon Shame All Websites That Are Unencrypted

#86
post #32

Earlier quoted context omitted.

Isn't that what Let's Encrypt is aiming for? Install a package, which configures a cronjob for you? https://letsencrypt.org/howitworks/ Which could just even become a default but optional dependency of your distro's web server package, or part of your Docker container, or whatever.

I tried to set up LE for my personal bunch of websites, but sadly the rate-limiting is still too strict for automation to be a viable option.

Huh, the rate limits look pretty generous (500 certs every 3 hours): https://community.letsencrypt.org/t/rate-limits-for-lets-enc...

Do you actually own hundreds of personal websites? (And you could still desync them, anyway.) Or is this a use case where wildcards would be useful. I sort of disagree with LE's decision to not care about wildcards for now, though I understand that it's simpler, at least while it's in beta.

Re: Google Will Soon Shame All Websites That Are Unencrypted

#87
Surely it could be a lot easier...

Everyone already has a known public third party authority -- their domain registrar. Surely the browsers could come up with some protocol where you generate your own keypair, register the public key with the registrar and keep the private key on the server.

Then it could work pretty much like SSH, but with the browser doing out-of-band public key checking. Rather than needing a certificate chain, the browser just checks the server's public key matches the published one. If ok, happy to encrypt. If not, wave flags, and yell "spoof".

Verifying the registrar isn't a fly-by-night can be as complicated as needs be, but that way the registrar (who already gets paid to register the domain) does the complex hassle, while the ordinary domain-buyer just has to keep their server's public key up-to-date with the registrar (ie, fill in one web form at the time you register the domain or whenever you change the server key).

But alas it is not so at the moment. Instead, the current process puts hassle onto millions of individual domain-owners, while keeping life easy for the few (paid) certifying authorities. And then we wonder why so few people want to do it.

Re: Google Will Soon Shame All Websites That Are Unencrypted

#88

This is how it always should have been. It was mind boggling that mixed content was "insecure" but HTTP was "secure." HTTP is and always has been insecure and should be marked as such. I know there are a few people who will moan and groan about how overkill HTTPS is, but this isn't about banning HTTP it is just about reminding users that they shouldn't be entering sensitive information into a HTTP site. Even phishing…

>It was mind boggling that mixed content was "insecure" but HTTP was "secure." HTTP is and always has been insecure and should be marked as such.

Why is it mind boggling?

Content served over HTTP is obviously less sensitive than content served over HTTPS, mixed content breaks HTTPS.

Re: Google Will Soon Shame All Websites That Are Unencrypted

#89
post #5

Is there a strategic business reason for this on Google's part other than a safer web is better for all? I don't doubt that a more secure web is better for everyone, I'm just more curious about the business drivers of this from their perspective. The reason I'm wondering is because with AMP, there seems to be a clear strategic benefit from having all of that ad serving data running through them even if the advertiser…

> Is there a strategic business reason for this on Google's part other than a safer web is better for all? The two common reasons for MitM are spying and inserting/replacing advertisements. The latter is stealing from Google, so they want to stop it before it grows too common.

We can only wonder how long it will be until Google starts openly advertising and buying newspaper articles against that new ad-replacing browser.
Post reply on HN