Live data from Hacker News

Bypassing Browser Security Warnings with Pseudo Password Fields

troyhunt.com

81–90 of 127 posts

Re: Bypassing Browser Security Warnings with Pseudo Password Fields

#81
post #37

"I’ve been speaking with the owner about SSL before I invest in becoming a member, but she’s been told by the dev of the platform (it’s a franchise system called ShopCity.com) that SSL is more about Google’s monopolizing visibility of content, and less to do with security" This is an interesting observation of how Google's technical crusades often align with its profit interests. The main threat that HTTPS everywhere…

I don't want my ISP to inject JavaScript to random pages or analyze my traffic. That should be downright illegal. They should be like water supply company: provide me damn clean water and get out of my way. Somehow the sewage company doesn't analyze my urine (I hope ) to figure out if I prefer spicy or sour food and get an extra buck from third parties, and somehow they're still in the business .

> I don't want my ISP to inject JavaScript to random pages or analyze my traffic. That should be downright illegal. They should be like water supply company: provide me damn clean water and get out of my way.

I don't want my search engine to do that either. They should provide me damn accurate results and get out of my way.

Unfortunately, whereas I have a choice of several good ISPs here (UK), I have a choice of precisely one good search engine - Google - and it analyses my traffic to high heaven. (And I've tried DuckDuckGo, on several occasions for several weeks at a time, and I'm afraid it still sucks.)

Re: Bypassing Browser Security Warnings with Pseudo Password Fields

#82

"I’ve been speaking with the owner about SSL before I invest in becoming a member, but she’s been told by the dev of the platform (it’s a franchise system called ShopCity.com) that SSL is more about Google’s monopolizing visibility of content, and less to do with security" This is an interesting observation of how Google's technical crusades often align with its profit interests. The main threat that HTTPS everywhere…

> The main threat that HTTPS everywhere secures against is preventing your ISP from analyzing your traffic in order to build and sell an advertising profile on you. As someone living in Europe, this literally happens nowhere. Because it's illegal. SSL in browser has nothing to do with our ISPs. Stop being US-centric.

Yeah, no way that would happen in Europe.

Oh wait.

http://www.telegraph.co.uk/technology/news/8438461/BT-and-Ph...

Re: Bypassing Browser Security Warnings with Pseudo Password Fields

#83

Earlier quoted context omitted.

> (b) a mistaken sense of principle of standing up to the perceived bulliness of Google, which, come to think of it, it's basically an application of (a) But Google has been bullying around with their behaviour. I don't think that's even debatable.

They have been bullying around, but their enforcement of HTTPS for forms with password inputs shouldn't count as one of their instances of bullying. It's something browser vendors should have implemented long ago, even before LetsEncrypt came along, because it is highly insecure and users should know about it.

Fortunately Google is consistent about enforcing encryption anywhere where passwords could be intercepted.

Oh, wait.

http://blog.elliottkember.com/chromes-insane-password-securi...

And if you disagree with them, you're "a novice".

https://news.ycombinator.com/item?id=6166886

Re: Bypassing Browser Security Warnings with Pseudo Password Fields

#84

Earlier quoted context omitted.

They have been bullying around, but their enforcement of HTTPS for forms with password inputs shouldn't count as one of their instances of bullying. It's something browser vendors should have implemented long ago, even before LetsEncrypt came along, because it is highly insecure and users should know about it.

Fortunately Google is consistent about enforcing encryption anywhere where passwords could be intercepted. Oh, wait. http://blog.elliottkember.com/chromes-insane-password-securi... And if you disagree with them, you're "a novice". https://news.ycombinator.com/item?id=6166886

That article is from 2013. You can set a master password on Chrome now. It then requests that password whenever you wish to view a password in the manager.

If you don't set a master password, then your passwords are (presumably) encrypted with your google account. So anyone using Chrome that's logged into your google account will be able to view the passwords via settings. So just don't let malicious users use your Chrome?

Edit: And there's also a guest mode for Chrome, but they can just exit out of the window and run a regular instance of Chrome to use it under your profile.

Re: Bypassing Browser Security Warnings with Pseudo Password Fields

#85
post #79

Edit: Ignore this. It seems most of the posts I was talking about were either deleted or edited. Keeping my original message here for completeness sake. --- The number of people saying that this is a clever workaround and agreeing with the people putting in the bug reports is very disheartening to see on HN. If a highly technical crowd such as HN can't get why HTTPS is important than what hope does everyone else have…

> The number of people saying that this is a clever workaround and agreeing with the people putting in the bug reports is very disheartening to see on HN Huh? I've been through this entire thread and I haven't seen anyone suggest that this is acceptable behavior; even in the heavily-downvoted comments. It's mostly just people laughing at the lengths this site went to to shoot itself in the foot.

Wow... looking at it now I don't either. I don't know if they got flagged or deleted or editor of what. One of the comments in particular I can see was clearly edited to be more clear that they thought it was a bad idea.

Re: Bypassing Browser Security Warnings with Pseudo Password Fields

#86

"I’ve been speaking with the owner about SSL before I invest in becoming a member, but she’s been told by the dev of the platform (it’s a franchise system called ShopCity.com) that SSL is more about Google’s monopolizing visibility of content, and less to do with security" This is an interesting observation of how Google's technical crusades often align with its profit interests. The main threat that HTTPS everywhere…

> The main threat that HTTPS everywhere secures against is preventing your ISP from analyzing your traffic in order to build and sell an advertising profile on you. That is not true. The main threat it protects against is MitM (man in the middle attacks) that allow someone to redirect all traffic to a website through their machine and thus see all the data including your password. HTTPS when combined with root certif…

I'm not sure you understood his point..

Re: Bypassing Browser Security Warnings with Pseudo Password Fields

#87
post #70

Earlier quoted context omitted.

So far you're following the anti-vax script perfectly: lots of FUD, no claims specified in enough detail to even evaluate them much less counteract the overwhelming evidence that vaccines are a public good with no reputable downside.

I've been supplying information and you've been complaining. I fail to see how I'm at fault for trying to answer questions.

You didn't just talk about the debate. You stated as a fact that many vaccines have improper testing or substances. If you state something as a fact, you should be prepared to back it up.

Re: Bypassing Browser Security Warnings with Pseudo Password Fields

#88
post #56

Earlier quoted context omitted.

> I don't want my ISP to inject JavaScript to random pages or analyze my traffic. I haven't seen a single reputable ISP do this anywhere. It would illegal. Is the US really such a third world nation that not even basic regulation like this exist?

I used to have internet from Cox Communications. One day when I was working from home, I was surprised to see a page in my local dev environment load with an overlay telling me my ISP thinks I have a Windows virus (I didn't own any Windows machines at the time). Turns out our dev environment didn't force CDN assets to load over HTTPS, so my ISP injected some JS into a library we were loading. I tweeted at them, and t…

"With respect to your complaint that Cox intercepts and injects our own data in order to display alerts, etc, we note that browser alerts are a method Cox utilizes to bring customers’ attention to important information that may affect their Internet experience."

They'll also appear if you're nearing your data allowance or if their email service (that you probably don't use) is undergoing maintenance. When I last asked, there is no possible way to opt-out or disable these.

Re: Bypassing Browser Security Warnings with Pseudo Password Fields

#89
post #58

Earlier quoted context omitted.

> As a side note, the debate is not that simple. Vaccines work, but many vaccines are manufactured without what many would consider proper testing, and using toxic substances banned in different countries. Those are big claims without any supporting evidence. From the sounds of it, you're repeating the anti-vax claims about mercury.

Ethyl vs Methyl mercury is one of the most popular debates (because mercury is scary!). Most vaccines switched to Thiomersal which has ethylmercury in it. However, even ethylmercury crosses the blood-brain barrier. Other 2 big ingredients are formaldehyde and aluminum. From there you have to get more specific about which vaccine you are talking about.

There's more mecury in the fish you eat and it's the methyl kind which sticks around for weeks. If you eat fruit, there's methanol naturally present which the body metabolizes into formaldehyde. I am willing to bet your kid gets a higher dosage of formaldehyde from the juices they drink then a vaccine.

Re: Bypassing Browser Security Warnings with Pseudo Password Fields

#90
post #52

Earlier quoted context omitted.

:empty is for elements with no children, not empty value.

You could potentially use the validation rules, and set a min length of 1.

You'd need [required] instead of [minlength] for :valid to work. The other option is :placeholder-shown, to style no-input normally, but it's newer and not as supported.
Post reply on HN