12 ms·
I’d like to defend this guy. What he is doing is testing the trust mechanism. If he went to Google and said ‘I think the trust mechanism is broken’ Google wou
by GedByrne 8y ago
I’d like to defend this guy. What he is doing is testing the trust mechanism.
If he went to Google and said ‘I think the trust mechanism is broken’ Google would say: ‘We know, that’s why we are pushing to move everyone to https.’
‘That isn’t enough. The padlock on the https page gives users a false sense of security.’
‘We don’t agree with that. Where’s your data?’
Google wouldn’t have accepted this. They have pushed full HTTPS hard, and suggesting that it has a negative consequence is unacceptable to them.
His experiment has proven the problem. How else could it have been demonstrated?
Ideally this would have been a large scale study done by academics. But this guy doesn’t have those resources. Nobody is going to fund this research.
The depressing thing here is that everybody is more interested in calling this guy a jerk than dealing with the issues he has raised.
Trust on the internet is broken. This guy did it with ease. Imagine what is being done by those who want to scam
millions?
But yeh, call him a jerk and then you can bury your unease beneath a big pile of outrage. It’s fine. Fine. He’s a jerk.
- chmike 8y agoIt looks indeed like "The Emperor's New Clothes" story of Anderson [https://en.m.wikipedia.org/wiki/The_Emperor%27s_New_Clothes https://en.m.wikipedia.org/wiki/The_Emperor%27s_New_Clothes].
- Klathmon 8y agoSo you are implying that HTTPS made this attack easier or more impactful? I don't buy it. This same attack would work the same with or without HTTPS having existed, and the only reason it wouldn't work as well in practice is because HTTPS is a baseline of security. It's like saying that airbags cause people to trust unsafe cars. An HTTP only site is a red flag now, but HTTPS just means it won't be instantly considered untrustworthy. HTTPS has massive benefits, and Google is already starting to "deprecate" the green padlock (IIRCthey have plans for HTTPS to be "normal" with no green padlock and HTTP to be marked as "unsafe").
- palotasb 8y agoThere is a similar debate about making wearing bicycle helmets mandatory. [1] One problem is basically that with cyclists wearing helmets, they and drivers around them might think that smaller safety margins are necessary. (Both physically as drivers drive closer to them and e.g., cyclists more likely to drive at unsafe speeds.) I think the argument here is the same: the green padlock makes people feel too safe. I could easily buy an argument that if HTTPS was not highlighted prominently as a SAFE thing by the browser, people would pay more attention to other indicators such as the domain when browsing the internet. [1] https://discerningcyclist.com/2018/05/mandatory-bicycle-helmets-laws-dont-make-cyclists-safer/ https://discerningcyclist.com/2018/05/mandatory-bicycle-helm...
- tialaramex 8y agoBut as your parent pointed out we _already know_ that padlocks for HTTPS are the wrong UI here. The goal is to get to the right UI, which you can only do after getting to very high HTTPS usage rates, which we've been working on for several years already. Tim's toy hypertext system from last century doesn't have confidentiality or integrity at all and the authentication mechanisms are garbage (which is why nobody uses them). So adding these necessary features has been a retro-fit for the past 20 years or so, and unfortunately the original attempt at the retro-fit was done by people who knew nothing about security UX. Which is understandable, this was the era when people thought PGP was usable. So, we have to get from this cul-de-sac we were in 10+ years ago, to the correct approach, which means some U-turns and all the major browser vendors are more or less on board with that. The padlock will go away (at least from the main UI) as part of the journey, but it hasn't gone away yet because we're not finished. Notice that even going as slowly as we have, every time there's an incremental move Hacker News is full of people screaming about how awful this is, they can't be expected to handle this pace of change...
- dejanseo 8y agoThank you. I'm not having a good time at the moment. Anyway, the basis of my test hypothesis is that people are easily fooled by URL both by HTTPS and brand recognition (e.g. subdomain) so I conducted a survey which revealed the very real problem: https://dejanseo.com.au/trust/ https://dejanseo.com.au/trust/ Raw data: https://dejanseo.com.au/wp-content/uploads/2017/04/survey-texrixayf2f67gzehkadczhl5m.xls https://dejanseo.com.au/wp-content/uploads/2017/04/survey-te...
- moolcool 8y agoDon't listen to the haters here. The same people upvoted this article 3 days ago, and then promptly forgot about it https://news.ycombinator.com/item?id=17799083 https://news.ycombinator.com/item?id=17799083
- geofft 8y agoI think you'll find that a lot of people on this site—from lots of political leanings—believe there's a wide gulf between "This behavior is a bad idea and we should use social mechanisms like debate to discourage it" and "This behavior should be illegal and we should point the government's monopoly on violence in your face to make you stop." The flip side of the defend-to-the-death quote is that caring about someone's right to speak, even caring about that position being well-represented, doesn't mean you have to agree with what they say.
- dejanseo 8y agoThe irony...
- 3pt14159 8y agoHey man, I know how hard the hate hits when you explain something like this to a community. It happened to me here too when I talked about the mass weaponization of autonomous systems via cyber attack. One guy said I was somehow right and a crank at the same time and dismissed one of my conclusions out of hand without addressing any of the reasoning behind it. I hurt at the time, but I came to understand it wasn't really directed at me. The thing you got to realize is that many here make their livings trying to secure systems and we're finding it hopeless. The way you did what you did was fine. In terms of proving the hack you needed to violate Google's trademarks. It's in the very nature of the hack, and as far as I'm concerned, warranted given that they have a bug bounty. Now, I probably would have disclosed it to Google, Bing, etc. ahead of time, but it's your bug. You could have sold it to blackhat scammers and you didn't. For all we know this hack could have been going on for years. I think most people are confusing their anger at the situation with anger towards you. You're cool.
- SquareWheel 8y ago>‘That isn’t enough. The padlock on the https page gives users a false sense of security.’ >‘We don’t agree with that. Where’s your data?’ Where is your source that this is Google's position? Considering they have some of the best security employees in the business, I find that hard to believe.
- stestagg 8y agoAllowing sites to intercept browser actions that should make a user leave the site, and inject other operations is obviously and plainly a security issue. I reported this to google several years ago, and it was never addressed.
- deleted 8y ago[deleted]
- SquareWheel 8y ago>Allowing sites to intercept browser actions that should make a user leave the site, and inject other operations is obviously and plainly a security issue. Sure, I agree. But what does it have to do with the parent comment's claim? I've read much of the discussions involving the early push for HTTPS, and the developers involved were very fastidious.
- AndrewKemendo 8y agoThe point is that google should be penalizing sites that do that in search results, or at least in chrome with some kind of browser recognition - as the OP states in the article.
- SquareWheel 8y agoThey should do more than penalize them in search. They should add them to their malicious site list.
- geofft 8y ago
- real-hacker 8y agoRaising awareness is what he want, being called a jerk is the price he has to pay. Defend +1.
- justaguyhere 8y agoAgreed. Forget a huge, third party like Google, many times (at least in my experience) even our own bosses in small companies wouldn't listen. And even if they did listen, they wouldn't act. Unless of course, it is proven with data and it is big enough to cause them a headache. I'd guess mostly it is due to laziness and not any malicious intent.
- geofft 8y agoFWIW, "the padlock is enough" is quite the opposite of Google's position: https://blog.chromium.org/2018/05/evolving-chromes-security-indicators.html https://blog.chromium.org/2018/05/evolving-chromes-security-... and in fact one of the main reasons is that use of HTTPS is far too little information for the browser to affirmatively indicate "This site is secure and trustworthy." So they are planning to get rid of the padlock. (Use of HTTP is enough for the browser to affirmatively say it's insecure, though.) So I think Google understands that one of the consequences of pervasive HTTPS is that the padlock is at best meaningless and at worst misleading, as we saw here.
- Ibethewalrus 8y agoI can agree firsthand, people think a site, any site, is safe because of the padlock... :facepalm:
- _bxg1 8y agoGoogle has shown time and again that they're open and enthusiastic about receiving properly reported bug reports which give them the chance to fix things before hitting the web. Usually that includes compensation. Why would you think this one would be any different? Maybe this guy just wasn't familiar with proper practice, in which case, well, what can you do. But it's extremely bad to go public with bugs without talking to the vendor first. How many sites might exploit this between the blog post going live and Google rolling out a fix?
- drewmol 8y ago>Google would say: ‘We know, that’s why we are pushing to move everyone to https.’ Am I presuming too much to think Google's primary motivation for pushing HTTPS is to protect their revenue model by preventing their ads from being replaced as opposed to simply being motivated by benevolence?
- chrisweekly 8y agoFWIW I don't think he acted like a jerk at all. /$.02