Live data from Hacker News

Google Will Soon Shame All Websites That Are Unencrypted

motherboard.vice.com

1–10 of 369 posts

Re: Google Will Soon Shame All Websites That Are Unencrypted

#2
bingo

check and mate

TLS Certificate MITM Is now the fucking de-facto crypto

thats the end of the story as far as ssl/tls security goes.. you wont hear about it anymore.

and if you dont have it you are not trustworthy. thats it. no objections. no court hearing. youre just done.

(its probably a good time to bring up the W3C president states this is not https3 this is tls labeled as https. and the 4 show stopping bugs tls has had so far. the downgraded exploitable encryption for other countries. the noob crypto bugs like null nonce/reusing nonce and the other one i forget, the authors published MITM kit, or the open bug for 1 year in usersupplementaldata for a buffer overflow, and how the heartblood code was using variables 'payload' not 'buf' or 'msg' but you know those were already downvoted -15 on HN. could also bring the fact they pushed this into all the popular ssh clients and the ssl, and IRC, so now they are capturing way more ssh, irc, and ssl.)

Re: Google Will Soon Shame All Websites That Are Unencrypted

#3

bingo check and mate TLS Certificate MITM Is now the fucking de-facto crypto thats the end of the story as far as ssl/tls security goes.. you wont hear about it anymore. and if you dont have it you are not trustworthy. thats it. no objections. no court hearing. youre just done. (its probably a good time to bring up the W3C president states this is not https3 this is tls labeled as https. and the 4 show stopping bugs…

Sorry?

Re: Google Will Soon Shame All Websites That Are Unencrypted

#4
This is how it always should have been.

It was mind boggling that mixed content was "insecure" but HTTP was "secure." HTTP is and always has been insecure and should be marked as such.

I know there are a few people who will moan and groan about how overkill HTTPS is, but this isn't about banning HTTP it is just about reminding users that they shouldn't be entering sensitive information into a HTTP site.

Even phishing sites should be DV secure.

Re: Google Will Soon Shame All Websites That Are Unencrypted

#5
Is there a strategic business reason for this on Google's part other than a safer web is better for all? I don't doubt that a more secure web is better for everyone, I'm just more curious about the business drivers of this from their perspective.

The reason I'm wondering is because with AMP, there seems to be a clear strategic benefit from having all of that ad serving data running through them even if the advertisers and publishers are not using the DoubleClick stack or Google Analytics.

By bringing this to market from the standpoint of "improving" the mess publishers have brought upon themselves and speeding everything up, there's definitely a clear win for consumers here. That said, it leaves the door open for something similar to mobilepocolypse where Google updated their ranking signals on mobile to significantly favor mobile-friendly sites. I could easily see this going a similar route where it is a suggestion...until its not because if you don't implement it you'll lose rankings and revenue (and coincidentally feed Google all of your ad serving data in the process).

To be clear, I don't knock them for taking this approach, because if it works it is a very smart business move that will be beneficial to a lot of parties (not just Google). Just looking for other insights into the business strategy behind something like pushing for encryption, and AMP.

Re: Google Will Soon Shame All Websites That Are Unencrypted

#6
post #5

Is there a strategic business reason for this on Google's part other than a safer web is better for all? I don't doubt that a more secure web is better for everyone, I'm just more curious about the business drivers of this from their perspective. The reason I'm wondering is because with AMP, there seems to be a clear strategic benefit from having all of that ad serving data running through them even if the advertiser…

> Is there a strategic business reason for this on Google's part other than a safer web is better for all?

The two common reasons for MitM are spying and inserting/replacing advertisements. The latter is stealing from Google, so they want to stop it before it grows too common.

Re: Google Will Soon Shame All Websites That Are Unencrypted

#7
I think it's pretty funny that on the HN front page right now is a NYTimes article from the company's Google beat reporter about how trying to interview Larry Page is "emasculating" and then this announcement is accompanied by an image "shaming" the NYTimes web site for being unencrypted.

As to the feature itself, I don't think it's a big deal at all. We all know that the average internet denizen doesn't understand HTTPS at all and would just as likely ignore it as anything. The only people that would see and understand this new red X for what it represents would know that it doesn't really matter that the lolcat meme they just downloaded came through an unsecured channel.

Re: Google Will Soon Shame All Websites That Are Unencrypted

#9
Yeah. Still not paying for a cert on my person home-pages just so I can have my own page come up first when people google my (worldwide unique) name.

That page contains static HTML and does not need SSL, and it's not "insecure" just because you may be on a network which MITMs traffic. That makes your network insecure, not my page.

So yeah. Not interesting. Not worth it.

Post reply on HN