Live data from Hacker News

Encrypted web traffic now exceeds 90%

netmarketshare.com

81–90 of 311 posts

Re: Encrypted web traffic now exceeds 90%

#81

The Federal Government may not like this but this is heading to as it should be. Sometimes the government needs to be saved from itself!

I would say there is a 50/50 chance that the government has access to any http certificates that it needs to crack any https session that they would like to crack. The Patriot Act created secret courts to enable this type of stuff. They're well known to rubber stamp any warrant that comes through.

Re: Encrypted web traffic now exceeds 90%

#82
post #5

Good news for sure, but note that this isn't a total Internet scan: > We collect data from the browsers of site visitors to our exclusive on-demand network of analytics and social bookmarking products. More details about their samples: https://netmarketshare.com/methodology I would be more inclined to trust sources like https://transparencyreport.google.com/https/overview and Firefox Telemetry which come directly fro…

It's especially weird that their methodology reports "0% secure" traffic as recently as June 2016.

Re: Encrypted web traffic now exceeds 90%

#83
post #67

I don't know why so many people here are patting themselves on the back over this. This is not the kind of encryption people were talking about in the 90s and 00s. A lot of this encryption is not point-to-point. It merely secures user's interaction with some middleman (or their server). What would the numbers be if you subtracted all the traffic that can be snooped on by Google, Amazon and Cloudflare?

What are you talking about about? I think you better look up how https/tls works??? Sure you have to trust the certificate authority. Also can you imagine the scandal that would erupt if Google or AWS cloud was discovered to be eavesdropping on companies running things in their cloud? I don't think so.

> can you imagine the scandal that would erupt if Google or AWS cloud was discovered to be eavesdropping on companies running things in their cloud

Remember the "SSL added and removed here" image?

https://thumbs.mic.com/MTBjNTQzNTMzZiMvbWVtejZOdjJsaUdUVkZEa...

Re: Encrypted web traffic now exceeds 90%

#85
post #67

I don't know why so many people here are patting themselves on the back over this. This is not the kind of encryption people were talking about in the 90s and 00s. A lot of this encryption is not point-to-point. It merely secures user's interaction with some middleman (or their server). What would the numbers be if you subtracted all the traffic that can be snooped on by Google, Amazon and Cloudflare?

[deleted]

Re: Encrypted web traffic now exceeds 90%

#86
post #67

I don't know why so many people here are patting themselves on the back over this. This is not the kind of encryption people were talking about in the 90s and 00s. A lot of this encryption is not point-to-point. It merely secures user's interaction with some middleman (or their server). What would the numbers be if you subtracted all the traffic that can be snooped on by Google, Amazon and Cloudflare?

What are you talking about about? I think you better look up how https/tls works??? Sure you have to trust the certificate authority. Also can you imagine the scandal that would erupt if Google or AWS cloud was discovered to be eavesdropping on companies running things in their cloud? I don't think so.

https://en.wikipedia.org/wiki/Global_surveillance_disclosure...

Re: Encrypted web traffic now exceeds 90%

#87
post #67

I don't know why so many people here are patting themselves on the back over this. This is not the kind of encryption people were talking about in the 90s and 00s. A lot of this encryption is not point-to-point. It merely secures user's interaction with some middleman (or their server). What would the numbers be if you subtracted all the traffic that can be snooped on by Google, Amazon and Cloudflare?

What are you talking about about? I think you better look up how https/tls works??? Sure you have to trust the certificate authority. Also can you imagine the scandal that would erupt if Google or AWS cloud was discovered to be eavesdropping on companies running things in their cloud? I don't think so.

I believe the OP is talking about encryption for user data, not merely for transport.

Google, Amazon, &tc still store user data uninhibited and though they are often competent about security, they also often provide data to state actors as a normal course of action. The fact the a web browser communicates safely with an endpoint doesn't mean that endpoint isn't a bad apple itself. In some cases these endpoints are logging proxies to other servers and services, and though transport is again encrypted, the data is normally accessible by operators of such services.

Cloud computing has taken away the ownership of data from individuals, and that sounds like it has seeds of some kind of a revolution brewing.

Re: Encrypted web traffic now exceeds 90%

#88
post #77
post #67

I don't know why so many people here are patting themselves on the back over this. This is not the kind of encryption people were talking about in the 90s and 00s. A lot of this encryption is not point-to-point. It merely secures user's interaction with some middleman (or their server). What would the numbers be if you subtracted all the traffic that can be snooped on by Google, Amazon and Cloudflare?

You're not wrong, but the realistic alternative is having it the same way, just without any encryption.

Which is fine too, since not all communication needs to be secure (even on the internet).

These numbers are meaningless without a proper context and can potentially create a "security theater".

Re: Encrypted web traffic now exceeds 90%

#89

I wonder how many fuel is burned to power servers and browsers to constantly encrypt and decrypt data which could be transferred much more efficiently unencrypted.

Not much with modern processors. And it's worth it, you can't put a price on privacy and rights to it.

Re: Encrypted web traffic now exceeds 90%

#90
post #77
post #67

I don't know why so many people here are patting themselves on the back over this. This is not the kind of encryption people were talking about in the 90s and 00s. A lot of this encryption is not point-to-point. It merely secures user's interaction with some middleman (or their server). What would the numbers be if you subtracted all the traffic that can be snooped on by Google, Amazon and Cloudflare?

You're not wrong, but the realistic alternative is having it the same way, just without any encryption.

Yes but in this case caching proxies and other distributed approaches still would work out of the box as alternatives to cdns. I am not sure what I have gained. Nobody cares about end to end email encryption. This would be a real benefit, but Google could not build profiles so easily...
Post reply on HN