4 ms·
"Why isn't HTTPS everywhere yet?": Because it makes absolutely no sense for the vast majority of online content. Email in https ? Sure. Reading news sites in ht
by xroche 11y ago
"Why isn't HTTPS everywhere yet?": Because it makes absolutely no sense for the vast majority of online content. Email in https ? Sure. Reading news sites in https ? Accessing RFC in https ? My favorite online recipe site in https ? A total waste of money and CPU.
Oh, and sure, the problem has been "solved" for few geeks using the latest browsers accepting let's encrypt certificates. Sure.
- drdaeman 11y ago> Because it makes absolutely no sense for the vast majority of online content. Hey, not so fast with conclusions, please. Do you want an ISP filling your recipe reading with their advertisements. Nope? Or a random dude spoofing a Starbucks WiFi hotspot and serving you a malware on what you think is a trusted download site. Still no? That's what TLS is for. Not for random paranoid geeks or "just email and online payments" security. Oh, but, yes, Let's Encrypt is not yet completely production grade and still have some compatibility issues with older systems. Currently the only non-paid options I know are WoSign and StartSSL.
- rplnt 11y ago> Do you want an ISP filling your recipe reading with their advertisements. Thought this would go in a direction where your ISP changes the ingredients :)
- dspillett 11y agoIf there is a fraction of a $ to be made per instance by replacing references to (for example) Nutella with references and referral links to some other spread I'm sure it would happen somewhere, and might change the outcome of the recipe in terms of taste/texture or worse make people ill if a recipe avoiding particular allergens ends up with the wrong product being recommended.
- deleted 11y ago[deleted]
- pdkl95 11y ago> Because it makes absolutely no sense for the vast majority of online content. So you use postcards for most "the vast majority" of your snail (postal service) mail, right? Because envelopes[1] make "absolutely no sense"? Besides the security issues that have already been mentioned of someone modifying the content as a MITM - something which ISPs are already doing[2] - this is really just another version of the "If you have nothing to hide..." falacy. You do have things to hide, because you shouldn't let every node that handles your traffic compile a database of your browsing activities. [1] https://www.philzimmermann.com/EN/essays/WhyIWrotePGP.html https://www.philzimmermann.com/EN/essays/WhyIWrotePGP.html [2] e.g. "X-UIDH" and the various ISPs that inject javascript for various reasons.
- brians 11y agoActually, yes. The vast majority of snail mail I receive is open catalogs and other junk mail. Its content is entirely public.
- kardos 11y agoEven if you don't care about secrecy/privacy, things like this [1,2] and this [3] are reasons to do everything under HTTPS. [1] https://news.ycombinator.com/item?id=10926696 https://news.ycombinator.com/item?id=10926696 [2] https://labs.mwrinfosecurity.com/blog/2013/09/24/webview-addjavascriptinterface-remote-code-execution/ https://labs.mwrinfosecurity.com/blog/2013/09/24/webview-add... [3] https://mitmproxy.org/ https://mitmproxy.org/