6 ms·
Seriously? And what about Man-in-the-middle attacks? I mean come on, there are files to download from that website? How can I know if the site I see is REALLY y
by skeeks 7y ago
Seriously? And what about Man-in-the-middle attacks?
I mean come on, there are files to download from that website? How can I know if the site I see is REALLY your site without https?
Really, I don't know why you just don't obtain a Let's Encrypt certificate, it's not difficult anymore...
- moviuro 7y ago> How can I know if the site I see is REALLY your site without https? HTTPS has never been about non-repudiation or authenticity; it's always been about confidentiality. You get some half-assed "authenticity" if you didn't mistyped the domain, and your clock is correctly set, and the certificate authority wasn't compromised, and the web server wasn't compromised, etc. You should use GPG or signify if you need authenticity. HTTPS just prevents injection and monitoring, a bit (see SNI, sniffing downloaded sizes, etc.).
- anderskaseorg 7y agoConfidentiality without authentication is not a thing. If I don't know that I'm talking to you, then I might be talking to a MITM attacker who's reading everything we're saying (and may or may not be altering it). It really is that simple.
- Karunamon 7y agoSure it is. Imagine a website with a self signed cert. You're over HTTPS and still encrypted, but it's you vs the (statistically unlikely) MITM entity holding that cert's private key, rather than you vs everyone in traceroute running wireshark. It's strictly better. Granted this meant more before the days of LE, but you get what I'm saying.
- lvh 7y agoNon-repudiation and authenticity are terms of art. By redefining them well outside of what everyone else means by those terms, I don't think you're helping discourse along. HTTPS _absolutely_ guarantees non-repudiation and authenticity. Casually dismissing the most important protocol on the Internet as giving you some "half-assed authenticity" is pretty silly, especially when one of your suggested alternatives is GPG, which literally can not get a damn MAC right in any mode actually deployed anywhere and instead has some weird superstitious MDC nonsense.
- moviuro 7y ago> HTTPS _absolutely_ guarantees non-repudiation and authenticity No it doesn't. Correct HTTPS (i.e. connecting to a site with no errors) guarantees: * the entity that requested the certificate at the date it did had control over either the website or the DNS for a domain (if it is domain-squatting, it's even legal) * the Certificate Authority that did deliver that certificate did not suffer a breach; and otherwise followed protocol (CAA - which might be under attack, etc.) * the client connecting did either: not check for revocation (often), not encounter errors while checking, or silently ignored the absence of reply when asking for the CRL/OCSP responder And it's precisely because HTTPS doesn't guarantee any kind of authenticity that browsers themselves are dropping visual clues for EV certificates. [0] [0] https://www.troyhunt.com/extended-validation-certificates-are-really-really-dead/ https://www.troyhunt.com/extended-validation-certificates-ar...
- lvh 7y agoAs I stated in my original comment: sure, if you arbitrarily redefine what terms mean, HTTPS doesn’t provide authenticity or non-repudiation.
- johncolanduoni 7y agoAnd if someone palms your GPG private key, or the public key is not properly authenticated in the first place, you don't get any of the kind of absolute authenticity you're talking about either. You complain about CRL/OCSP, but a GPG keyserver has all the same flaws (with worse default configuration of clients).
- yjftsjthsd-h 7y ago.... you propose that HTTPS is insecure because someone could compromise the website, server, or CA? That precludes... pretty much everything from being "secure". If an attacker can compromise a website and CA, we should assume that they can compromise every other website and every software update server, thereby compromising >90% of computers on Earth inside a week, starting with anything connecting to the Microsoft and Ubuntu update servers.