Live data from Hacker News

History of HTTPS Usage

jefftk.com

1–10 of 27 posts

Re: History of HTTPS Usage

#5
> This allowed for an enormous amount of things, but online shopping wasn't one of them. The problem was, sending credit card numbers over HTTP opened them up to theft: anyone between you and the server could keep a copy of your card information.

In the 90s, what exactly would the attack vector have been? I don't imagine AOL would have wanted to steal people's credit cards. I find it odd that this was viewed as a concern for credit cards but not website logins.

Re: History of HTTPS Usage

#6

> This allowed for an enormous amount of things, but online shopping wasn't one of them. The problem was, sending credit card numbers over HTTP opened them up to theft: anyone between you and the server could keep a copy of your card information. In the 90s, what exactly would the attack vector have been? I don't imagine AOL would have wanted to steal people's credit cards. I find it odd that this was viewed as a con…

People genuinely worried about this. If you go back to around the time SSL is announced, the media coverage says well, you can't really have shopping on the Internet because there's no way to secure credit card purchases. Clifford Stoll has a rant from around then in which he just plain asserts it will never happen, even though that's actually written IIRC after SSL shipped.

A few years later it's much more about whether this is really going to take off, there's no doubt people can do it, but is there any desire? There's a BBC clip on Youtube from the era when Amazon is an exciting new business, it has a lot more different books in stock than any bricks and mortar store, but it doesn't have the enormous sales volumes compared to real world book stores yet, Bezos could just be another entrepreneur with an idea that sounds good - he isn't yet incredibly rich and so he also seems much less weird.

Re: History of HTTPS Usage

#7

> This allowed for an enormous amount of things, but online shopping wasn't one of them. The problem was, sending credit card numbers over HTTP opened them up to theft: anyone between you and the server could keep a copy of your card information. In the 90s, what exactly would the attack vector have been? I don't imagine AOL would have wanted to steal people's credit cards. I find it odd that this was viewed as a con…

While it's certainly possible the ISP could extract the data (and might be forced to by some intelligence agency), it was also possible to just listen to the data in transit. Remember that these were the days of people sending data over telephone wires.

Re: History of HTTPS Usage

#8

> This allowed for an enormous amount of things, but online shopping wasn't one of them. The problem was, sending credit card numbers over HTTP opened them up to theft: anyone between you and the server could keep a copy of your card information. In the 90s, what exactly would the attack vector have been? I don't imagine AOL would have wanted to steal people's credit cards. I find it odd that this was viewed as a con…

While it's certainly possible the ISP could extract the data (and might be forced to by some intelligence agency), it was also possible to just listen to the data in transit. Remember that these were the days of people sending data over telephone wires.

Other than eavesdrop, the biggest advantage of HTTPS for me is to stop nasty ISP that injecting advertisement or other code in HTTP page.

Re: History of HTTPS Usage

#9

> This allowed for an enormous amount of things, but online shopping wasn't one of them. The problem was, sending credit card numbers over HTTP opened them up to theft: anyone between you and the server could keep a copy of your card information. In the 90s, what exactly would the attack vector have been? I don't imagine AOL would have wanted to steal people's credit cards. I find it odd that this was viewed as a con…

While it's certainly possible the ISP could extract the data (and might be forced to by some intelligence agency), it was also possible to just listen to the data in transit. Remember that these were the days of people sending data over telephone wires.

> it was also possible to just listen to the data in transit. Remember that these were the days of people sending data over telephone wires.

It's that easy to tap a phone line?

Mail order services will take credit card numbers over the phone verbally, right? Why was that considered safer?

Re: History of HTTPS Usage

#10
post #2

[2018]

Aha. I was surprised to see that ~30% of web pages loaded by Firefox were still not https. A 6-year-old graph would explain why!

Apparently 10% is still unencrypted which is higher than I would have thought... https://letsencrypt.org/stats/
Post reply on HN