3 ms·
I believe it's either (a) a lack of understanding of _why_ one should use SSL or (b) a mistaken sense of principle of standing up to the perceived bulliness of
by robteix 9y ago
I believe it's either (a) a lack of understanding of _why_ one should use SSL or (b) a mistaken sense of principle of standing up to the perceived bulliness of Google, which, come to think of it, it's basically an application of (a)
- josteink 9y ago> (b) a mistaken sense of principle of standing up to the perceived bulliness of Google, which, come to think of it, it's basically an application of (a) But Google has been bullying around with their behaviour. I don't think that's even debatable.
- prophesi 9y agoThey have been bullying around, but their enforcement of HTTPS for forms with password inputs shouldn't count as one of their instances of bullying. It's something browser vendors should have implemented long ago, even before LetsEncrypt came along, because it is highly insecure and users should know about it.
- throwaway6845 9y agoFortunately Google is consistent about enforcing encryption anywhere where passwords could be intercepted. Oh, wait. http://blog.elliottkember.com/chromes-insane-password-security-strategy http://blog.elliottkember.com/chromes-insane-password-securi... And if you disagree with them, you're "a novice". https://news.ycombinator.com/item?id=6166886 https://news.ycombinator.com/item?id=6166886
- prophesi 9y agoThat article is from 2013. You can set a master password on Chrome now. It then requests that password whenever you wish to view a password in the manager. If you don't set a master password, then your passwords are (presumably) encrypted with your google account. So anyone using Chrome that's logged into your google account will be able to view the passwords via settings. So just don't let malicious users use your Chrome? Edit: And there's also a guest mode for Chrome, but they can just exit out of the window and run a regular instance of Chrome to use it under your profile.
- aaronmdjones 9y ago> It's something browser vendors should have implemented long ago Netscape Navigator did this (almost) 20 years ago. EDIT: Link. http://www.kentlaw.edu/faculty/rwarner/classes/legalaspects/digital_signatures/VeriSign%20OnSite%20for%20Secure%20Server%20IDs_files/fig2.gif http://www.kentlaw.edu/faculty/rwarner/classes/legalaspects/...