3 ms·
How else would you practically verify integrity for web browsing? What's wrong about caring about your privacy?! Why the hell do ISPs deserve ad revenue? I do
by floatboth 9y ago
How else would you practically verify integrity for web browsing?
What's wrong about caring about your privacy?!
Why the hell do ISPs deserve ad revenue? I don't like Google either, but ISPs that want to tamper with connections to inject their ads can fuck off and die in a fire. That is more unethical than anything Google has ever done.
- peterwwillis 9y ago> How else would you practically verify integrity for web browsing? Download a signature once, verify any file before rendering it. You could even control this behavior using an HTTP header if you wanted granular control. It would be a trivial extension. Today, nobody verifies that content was created by the author. That content can be subverted on the web server, and this is how malware is distributed today. Verifying content with a signature would actually be more secure than just TLS. > What's wrong about caring about your privacy?! Ignoring all the other concerns for the sake of it, is what's wrong. > ISPs that want to tamper with connections to inject their ads can fuck off and die in a fire. That is more unethical than anything Google has ever done. Google reads your e-mails and search history and tracks where you go on the internet, and sells the information to advertisers, who then display the ads no matter where you are or what you're looking at - including over HTTPS pages.
- nsgi 9y agoThat functionality doesn't exist today, so it would be a new protocol. One that would be almost as complicated as HTTPS, would be starting from zero as opposed to the 50% usage of HTTPS on the internet, would require new code to be written which hasn't been thoroughly tested for security issues and would provide inferior assurance to HTTPS. All for the sake of being "simpler." With regards to signing content, this already exists in the form of code signing. Given the amount of software that isn't signed I doubt it would be practical for anything else e.g. blog posts.