4 ms·
Agreed completely, but Google don't care about "nice to have"; if it doesn't ultimately make them money, they couldn't care in the slightest, yet people here wi
by toby- 7y ago
Agreed completely, but Google don't care about "nice to have"; if it doesn't ultimately make them money, they couldn't care in the slightest, yet people here will often applaud this attitude as if it were progress.
- Someone1234 7y agoIt is progress though. FTP is insecure, and worse still it breaks the security model of HTTPS (see article for more info). Plus additional code paths could be sources of bugs/exploits, particularly old/rarely updated ones.
- jimmaswell 7y agoYou can justify removing anything with "less code paths." I hate that argument. Don't care about FTP being insecure either. Google's just being hostile to the open web as usual and getting the usual applause.
- dagenix 7y ago> Don't care about FTP being insecure either. Well, then its probably a good thing that you aren't a browser developer.
- TeMPOraL 7y ago"Insecure" is the new "is a witch". Too coarse to be used as a valid argument.
- clhodapp 7y agoAlright. It's not encrypted and not origin-verifiable then. I think we all knew that though... anyway it should be abundantly clear at this point that no one should be using protocols that can trivially be MITM'ed to access anything over the internet.
- Someone1234 7y agoOr involves the plain text transmission of passwords by design.
- dieFledermaus 7y ago>...anyway it should be abundantly clear at this point that no one should be using protocols that can trivially be MITM'ed to access anything over the internet. This is a specious argument because HTTP/HTTPS is regularly (and legally) MITM'ed[0, 1]. If we shouldn't use anything that can be MITM'ed, shouldn't we just shut down the internet? Wouldn't that stop MITM attacks permanently-like? What about phones? Or letters? Or even talking? Where does this scare-tactic of the MITM "boogey-man" end (for you)? [0] - https://www.symantec.com/products/proxy-sg-and-advanced-secure-gateway https://www.symantec.com/products/proxy-sg-and-advanced-secu... [1] - https://www.occrp.org/en/daily/10431-kazakh-officials-delay-suspicious-internet-security-requirement https://www.occrp.org/en/daily/10431-kazakh-officials-delay-...
- rrdharan 7y agoMoreover it's not implausible (I'd wager it's actually likely) that HP and other websites still relying on FTP will be pressured to actually fix their sites and switch to something more secure once Chrome drops support.
- kuschku 7y agoThey'll switch to links which require proper cookies and referers to be set making them impossible to wget. As they always do. Now that's so much better and more secure!