4 ms·
The simpler solution is to not run that code. The imaginary user cited does not need that code in order to "browse memes". The code is there for advertising,
by aplorbust 9y ago
The simpler solution is to not run that code.
The imaginary user cited does not need that code in order to "browse memes".
The code is there for advertising, e.g., to attract advertisers as customers by gathering data about users.
Hence the push to HTTPS is for companies that aim to generate revenue from selling access to or information about users to advertisers.
I have no problem with HTTPS on the public web, to the extent that it is the concept of encrypted html pages, and perhaps these are authenticated pages (PGP-signed was an early suggestion).
Encrypt a page of information (file), sign it with a public key and then send it over the wire . The wire (network) does not necessarily need to be secure.
However I do have a problem with SSL/TLS.
I would like to leave open the option to not use it in favor of alternative encryption schemes that may exist now or in the future. It seems one allegedly "user-focused" company wants to remove this option. Comply with their choice or be penalized.
The issue I have with TLS is only to the extent TLS is the idea of setting up a "secure channel" to some "authenticated" endpoint (cf. page), with this authentication process firmly under the control of commercial third parties, using an overly complex protocol suite and partial implementation that is continually evolving (moving target) while people scramble to try to fix every flaw that arises out of this complexity.
To the extent it is not what I describe, I have no issue. (That is, I'm pro-TLS.)
We have one company aiming to replace HTTP with their own HTTP/2 protocol, which to no surprise has features that benefit web app developers and the advertisers they seek to attract far more than they benefit users.
Could we design a scheme to encrypt users web usage that would not benefit advertisers? I think yes. But this is not what is being developed. Encryption today is closely coupled with the "ad-supported web". If we are not careful, this sort of policy pushing by Google could cripple the non-ad-supported web that existed before the company was incorporated.
Encrypted "channels" are not the only way to protect information transferred via the web. TLS is not the only game in town.