4 ms·
> And what's really annoying is that HTTPS doesn't really affect user security much. It mainly just affects privacy. Most people are not hacked by a man in the
by MrManatee 9y ago
> And what's really annoying is that HTTPS doesn't really affect user security much. It mainly just affects privacy. Most people are not hacked by a man in the middle. They're hacked by a person accessing a database, or running an authentic looking website, or exploiting a bug. So while a lot of headaches will be caused by adopting HTTPS everywhere, people won't necessarily be any safer.
Maybe I misunderstood, but it sounds like you're criticizing HTTPS for its success. People only rarely get hacked using man-in-the-middle attacks, because popular sites are already using HTTPS. If they didn't, I'm sure they would be MITM-hacked all the time.
- peterwwillis 9y agoMITM is a lot more work for a lot less payoff. Say you found a small ISP that allows DNS cache poisoning. Once you succeed you get X users over a day or two. It's still a fraction of users of a small ISP. With a botnet, they can collect hundreds of thousands to millions of users, and all they have to do is own one site. Or they can send spam all day and not have to own anything. Of course MITM is a concern, it's just not the biggest concern, IMO.
- MrManatee 9y agoAh, I wasn't really thinking about DNS cache poisoning. I was thinking about someone going to a public place (a school, a cafe, an airport), setting up a deceptively named Wi-Fi hotspot on their smartphone, and intercepting all non-HTTPS traffic that's going through. Maybe this is not a lucrative opportunity for someone who also has the skills to gather a botnet that consists of millions of computers. But this attack requires minimal skills. If Gmail didn't use HTTPS, there would be an easy-to-use Gmail hacking app. If Facebook didn't use HTTPS, there would be an easy-to-use Facebook hacking app. The risk of getting caught is small. And by going to the right place, there's a reasonable chance of targeting a particular person, which many would find appealing. I think that the only reason attacks like this aren't more common is that most of the high-value attack targets are already using HTTPS.
- AlfeG 9y agoI miss those days when sitting in a cafe with rooted android phone, I we're able to mess up with peoples Facebook and VK accounts by sniffing traffik.