4 ms·
Every HTTP site is insecure, that's OK and we all agree on that. But using HTTPS doesn't make a website magically secure, that is not enough. Thus there might
by azureel 10y ago
Every HTTP site is insecure, that's OK and we all agree on that.
But using HTTPS doesn't make a website magically secure, that is not enough. Thus there might be a false sense of security via this option.
> My mom opens browser
> Goes to http://www.example.com http://www.example.com
> Sees "insecure" flag, ok moves on.
> Than goes to https://shady.example.com https://shady.example.com
> Oh nice padlock icon you got there
> It's secure, I can give my credit card info.
Maybe I'm exaggerating. Anyway, it's a good start. HTTPS everywhere, let's encrypt!
- cmdrfred 10y agoDon't the people who own example.com also own shady.example.com? example.net would be a more likely case.
- seanwilson 10y agoMaybe one subdomain is served over HTTP and the other subdomain is served over HTTPS. Lots of sites still do this where the area you login to is under HTTPS but the rest is under HTTP.
- cmdrfred 10y agoComment specifies the protocol used "Than goes to https://shady.example.com" https://shady.example.com"
- azureel 10y agoYeap, you're right. I can correct the example; > Goes to http://example1.com http://example1.com > Than goes to https://example2.com https://example2.com How about this one?
- seanwilson 10y ago> But using HTTPS doesn't make a website magically secure, that is not enough. Thus there might be a false sense of security via this option. It's more that HTTP makes it impossible for the site to be secure but HTTPS raises the bar significantly. Google seem to be pushing for HTTPS to be the minimum standard of security.
- Klathmon 10y agoAt the end of the article they touch on a solution to that. Eventually they want to move toward a point where every HTTP site is marked insecure, and HTTPS is marked with a grey "normal" icon. Then there is no more false sense of security to the average person, just knowledge of which is insecure.
- tptacek 10y agoThis is why Chromium is moving towards warning on all unencrypted sites.
- lallysingh 10y agoThis is a terrible argument that harms everyone.
- deleted 10y ago[deleted]