4 ms·
The website serves JS and does not serve it over https, and discusses Spectre bug and how to patch it. I know he is the second most important guy on linux, but
by proginthebox 9y ago
The website serves JS and does not serve it over https, and discusses Spectre bug and how to patch it. I know he is the second most important guy on linux, but the irony.
- xroche 9y agoAnd you probably know much better than the second most important guy on linux what security means on the Internet: securing some javascript script on a random blog.
- axiomofquality 9y agoHTTPS should be expected by now - ISPs keep messing with my unencrypted traffic.
- lisper 9y agoThen you should get yourself a different ISP or a VPN.
- mjal 9y agoSome places have no other choices for ISPs. I don't disagree that a VPN would help but that feels like it's simply dismissing that there's a problem.
- AaronFriel 9y agoThis is an extremely easy thing to say for many people around the world. But for a large number of people - Americans, folks in countries with monopolies or state manipulation of internet traffic - it is not. Not everyone has a different ISP to choose from. VPNs are a risky proposition and can significantly reduce bandwidth and increase latency.
- sigmar 9y agoAnyone that thinks ISPs don't mess with traffic, should check out this malware research https://www.virusbulletin.com/conference/vb2017/abstracts/last-minute-paper-finfisher-new-techniques-and-infection-vectors-revealed/ https://www.virusbulletin.com/conference/vb2017/abstracts/la...
- deleted 9y ago[deleted]
- proginthebox 9y agoIt's not about that guy's blog. This causes desensitization to non-HTTPS traffic and when people then actually visit non-HTTPS malicious blog, they get infected. If all "trusted" websites were HTTPS, then whenever there was untrusted access, people will notice it and raise alarm.
- alphaalpha101 9y agoGiven that Javascript is a known attack vector for the very bugs he's talking about, yes apparently he does know better.
- boysabr3 9y agoOn a related note, accessing the site over Chrome will full site isolation can help protect against both bugs: https://support.google.com/faqs/answer/7622138#chrome https://support.google.com/faqs/answer/7622138#chrome
- dasil003 9y agoI get the irony, but if you could magically visualize the entire internet security threat matrix, this would fall so far down the list and his other work is so high in terms of impact, that it would absolutely no sense for him to take even one minute away from his other activities to address this.
- proginthebox 9y agoYes, hence my question. I have tried to setup a HTTPS service and it seems incredibly complicated if you have your own domain name. Even with lets encrypt, if you are using github pages for hosting but your own custom domain, you are out of luck. The point is not that he is not serious about security, point is, it is too hard to get normal security correct. And I am not talking about "cryptography is hard". I am talking about tools which should be easy and standardized. Those are hard.
- dasil003 9y agoWhat question?