6 ms·
Why is root-servers.org not https?
by Goopplesoft 11y ago
Why is root-servers.org not https?
- peterwwillis 11y ago.....Why would it be?
- macns 11y agoto protect a visitor's privacy
- medecau 11y agoOr to ensure that the content is not tampered.
- peterwwillis 11y agoNobody would tamper with this content.
- Buge 11y agoChina injected javascript malware into non-https traffic that joined the users into a botnet that launched a DDOS attack on Github. The "Great Cannon".
- peterwwillis 11y agoThe "Great Cannon" only targeted foreign traffic destined for Chinese websites. This one is not.
- Buge 11y agoYes but they just as easily could have targeted traffic to this site as well. Also a number of ISPs and wifi hotspots inject ads, and I know Verizon injected a tracking header based on your mobile plan.
- peterwwillis 11y agoSo Verizon is going to inject some 0day malware into this page to, what, serve you more ads? If you're concerned about tracking cookies or headers, get a plug-in to stop it. Every website on the planet should not need to use https just because Verizon wants to make money off targeted ads. And nobody is attacking this page to hack individuals. Of course you can. Security isn't about preventing every single possible attack from every possible angle. It's about making attacks more difficult when one is plausible or likely. Nobody will attack you through this particular website. So https is not needed to prevent a targeted attack.
- lenish 11y agoThat's not actually true. There have been several documented examples now of people injecting stuff into HTTP requests when they pass by (ISPs injecting notifications, ads, people running proxies injecting malicious javascript, etc).
- peterwwillis 11y agoIt's completely true. This content would never be targeted for MITM. It's a dashboard for displaying the global locations of DNS root servers and links to their authoritative organizations. Not only is this an incredibly niche site, all DNS root server information is replicated around the world by multiple organizations. Nobody uses this site to maintain their DNS trusts, it probably gets incredibly low traffic, and going out of your way to MITM it would be a lot of work for no payoff. This is a terrible target. Nobody would bother.
- lenish 11y agoIt's not strictly about targeted attacks. There are people who modify unencrypted content that passes through their system regardless of what content it is. There have been several presentations on this topic, but I'll link the slides for one [0]. Here's an article about an ISP injecting ads in case you don't think this sort of thing happens in real systems [1]. [0] https://www.defcon.org/images/defcon-17/dc-17-presentations/defcon-17-edward_zaborowski-doppelganger.pdf https://www.defcon.org/images/defcon-17/dc-17-presentations/... [1] http://arstechnica.com/tech-policy/2013/04/how-a-banner-ad-for-hs-ok/ http://arstechnica.com/tech-policy/2013/04/how-a-banner-ad-f...
- laumars 11y agoWhat privacy? Your IP and the hostname of the website you're connecting to isn't encrypted over HTTPS anyway. The content isn't sensitive and there's no cookies on the site. The only remotely personal data would be your accept language header (which could be guessed from your IP) and user agent string (which you can just spoof anyway if you're really that paranoid). The MITM argument has more merit, but even there I can't see it making much difference here given it's niche appeal. Plus given it's tech-savy bias, most people will be running a reasonably hardened system (latest patches, et al) anyway. Not the best argument against running TLS I'd admit; but still a point worth raising since the only argument for running HTTPS is to prevent malware injection. Obviously in an ideal world everything would be served under TLS. But let's be pragmatic about which sites we bully into switching.
- macns 11y agoYour IP and the hostname of the website you're connecting to isn't encrypted over HTTPS anyway. AFAIK website hostname is visible when using SNI.
- laumars 11y agoIndeed, but SNI is more than 10 years old now so very well supported. I'd appreciate someone else correcting me if I'm wrong here, but I believe SNI is also enabled by default (where it's supported). In any case, even without the hostname header, it doesn't take much research to find a short list of possible candidates (eg https://www.virustotal.com/en/ip-address/193.0.6.136/information/ https://www.virustotal.com/en/ip-address/193.0.6.136/informa...).
- macns 11y agoThanks for going deep into this, let me add though that it's not about an ideal world or bullying, HTTPS should be the default. Lets Encrypt managed that for us already, pretty soon it will be the default.
- bpicolo 11y agoYou transmit no secret information to it, and it none to you?