3 ms·
The problem with name-and-shame posts, other than their juvenile premise, is that you can read up on what the people in question say, and call the author on the
by sarcasmic 8y ago
The problem with name-and-shame posts, other than their juvenile premise, is that you can read up on what the people in question say, and call the author on their shit. Once you do this, you realize that one these objectors is not like the others, because once you discount the last few entrants' unjustified snake oil and utter quackery, you're left with Dave Winer's objections to Google's strategy on increasing the adoption of HTTPS by more and more explicit visual indicators of HTTP being 'non-secure' [1] and Mozilla's differently-worded, but comparable approach to 'deprecating' HTTP.
By cherry-picking his most abrasive soundbites and his most entitled-sounding Twitter replies, Scott handwaves away Dave's more reasoned frustrations, such as his 2016 lament [3] that his current webhost doesn't offer a no-cost, push-button way of enabling HTTPS, and that his long-runing, statically-hosted blog would now require ongoing maintenance to stay compliant with the ever-changing list of requirements Chrome and Mozilla set in service of a larger goal. He wonders that if UI changes don't have the effect Chrome and Mozilla are hoping for, will more drastic changes follow, like refusing to display HTTP pages altogether, and reading his words he doesn't appear to buy that static, read-only sites need strong assurances of identity and resistance from third-party tampering, especially not at the risk of potentially making access to those pages impaired in the most popular browsers forever.
Dave clearly questions the true motives of Google's promotion of HTTPS, but Scott is right that Google never said that they'd deprecate HTTP. But Mozilla did [2].
I don't agree with all of Dave's points, and I think that for most of the websites people these days actually visit, strong assurances of identity and resistance from third-party tampering are important. But it's unfortunate that Scott tries to present an uncharitable view of Dave's worldview, instead of letting his points stand on their merits.
[1] https://security.googleblog.com/2016/09/moving-towards-more-secure-web.html https://security.googleblog.com/2016/09/moving-towards-more-... [2] https://blog.mozilla.org/security/2015/04/30/deprecating-non-secure-http/ https://blog.mozilla.org/security/2015/04/30/deprecating-non... [3] http://scripting.com/liveblog/users/davewiner/2016/01/30/0956.html http://scripting.com/liveblog/users/davewiner/2016/01/30/095...
- shakna 8y ago> It should be noted that this plan still allows for usage of the “http” URI scheme in legacy content. Mozilla aren't deprecating access to HTTP, but rather new features for pages accessed over HTTP, features that can allow new attacks to surface for HTTP pages. You should also note no date has been set, since that document was written three years ago.