5 ms·
Surely a good thing since marking HTTPS as "secure" was always a bit misleading and normal users didn't understand that you were still subject to phishing attem
by Sol- 8y ago
Surely a good thing since marking HTTPS as "secure" was always a bit misleading and normal users didn't understand that you were still subject to phishing attempts and such even with an encrypted transport and authenticated servers.
Now it reflects the real world better: HTTPS is necessary but not sufficient for security, but with HTTP only you definitely don't have much security. I guess that's the best you can guarantee or communicate via the browser UI.
- ealhad 8y agoThis, exactly.
- dvfjsdhgfv 8y ago> marking HTTPS as "secure" was always a bit misleading This doesn't stop companies and many individuals calling HTTPS "secure".
- blntechie 8y ago> marking HTTPS as "secure" was always a bit misleading You are right but when the protocol name says 'Secure' right in its name, no wonder people market it as 'Secure'.
- jazoom 8y agoThe protocol is secure. The webpage, who knows?
- gaius 8y agoIndeed. Let’s Encrypt would happily issue a cert to scams4u.com provided only proof that the person making the request has control over the domain (that really is all they check). “Secure” implies far, far more than merely “encrypted”. The biggest security problems are behind the web server, not between you and it!
- mort96 8y agoI know it probably wasn't your intention to single out Let's Encrypt, but it's probably worth mentioning that almost any registrar, not just LE, would issue a certificate for a scam site, provided they can prove they own the domain.
- gaius 8y agoIt wasn’t always like that. In the 90s I remember to get a cert we had to pay a fee for a background check (Dun & Bradstreet, Companies House, etc). Obviously not foolproof but a massively greater assurance than anyone gets today.
- tazard 8y agoWould it be better if your phished credentials were MITM'd by a third party scammer due to being sent in clear text instead of going directly to the original scammers? I for one don't think so.
- gaius 8y agoOf all the recent high profile breaches, none would have been mitigated by HTTPS, or occurred anyway. Let me clarify that I don’t object to encryption - I object to telling the user “this site is secure” when there is no way to know that
- bad_user 8y agoHTTPS is about securing the connection to the website and NOT about identifying the website. It is sufficient for ensuring that intermediaries (e.g. your ISP) cannot meddle with the content being served (i.e. it's a form of signing the content for publishers), it ensures that the browsing stays private (with new DNS developments, the domain name stays private too) and it secures the data being sent (e.g. passwords). Nothing is sufficient for total security, but "HTTPS everywhere" is a vast improvement, going from zero security to almost sufficient security over night.
- swebs 8y ago>HTTPS is about securing the connection to the website and NOT about identifying the website. Unfortunately, it's both. Otherwise we would have had widespread encrypted connections decades ago. I'm not sure why browsers decided that no encryption is just fine, but encryption with a self-signed certificate triggers warnings that it's the end of the world.
- lordlimecat 8y agoBecause negotiated encryption is useless if you can't be sure you're talking to the right person. If you are using a self-signed cert with an unknown thumbprint, how does the other side know you aren't a MITM attacker?