4 ms·
Why don't I like this? I don't think it's HTTPS.... I think I don't like that one company has this much power over the web. This seems awfully familiar...
by bphogan 11y ago
Why don't I like this?
I don't think it's HTTPS.... I think I don't like that one company has this much power over the web.
This seems awfully familiar...
- sdrothrock 11y agoI don't like this because I've always thought that HTTPS shouldn't be a mandatory baseline. It doesn't make a whole lot of sense to me that a random website with no financial transactions or anything should require HTTPS. [Edit: And thus, it makes less sense to me that the site should be penalized by anyone for NOT having it.] "Ah, yes. Bob's Trivia Emporium has HTTPS. I know this is really Bob's site and that the data is from his site." If anyone has compelling arguments to the contrary, I'm open to hearing them.
- frankchn 11y agoHTTPS assures the integrity of the data transferred is from the origin domain, so it prevents your ISP from injecting additional ads into tour site, which some ISPs like to do [1]. [1]: http://arstechnica.com/tech-policy/2014/09/why-comcasts-javascript-ad-injections-threaten-security-net-neutrality/ http://arstechnica.com/tech-policy/2014/09/why-comcasts-java...
- sdrothrock 11y agoThat doesn't convince me; it's like saying every Tom, Dick, and Harry should get encrypted phones because Verizon has the capability to tap into conversations. The onus should be on the provider, not the customer.
- nickik 11y agoYou dont think that normal user should use encrypted phone sevices? Are you serious?
- srj 11y agoSuppose you go to Bob's trivia emporium in your browser and a MITM inserts malicious javascript content into the response. Looked at another way: Is there any reason http should not be secured with some sort of privacy and integrity check?