4 ms·
While at the begining I thought I sensed a bigger argument here, the further I read I am certain the author either prefers to discount MITM or lacks the underst
by omk 7y ago
While at the begining I thought I sensed a bigger argument here, the further I read I am certain the author either prefers to discount MITM or lacks the understanding of the full scope of a MITM. I agree that there are other evils of the web but that does not mean we make trade-offs.
The last paragraph goes as far as to say
"The ad is not from the website; rather, it is inserted into the datastream — after it has left the Web server as it streams the web page to your computer — by your own Internet Service Provider (Optimum in my case). This is called "watermarking", a variation on the classic Man-in-the-Middle attack. So far it's an infrequent occurrence and not a major problem, and in any case definitely not a security risk, just Yet Another Annoyance"
You let go of your user's privacy and security the moment you make such a trade-off calling it just another annoyance. While visiting this site a MITM could possibly inject a malicius javascript or sticky cookie. How is that just an annoyance? Protecting this is the biggest selling point of HTTPS.
- phh 7y agoI don't agree with the article (mainly because I consider that switching to https is free enough for anyone doing web hosting), but still, the point is pretty clear. https feels like red herring. When we say "MITM" who is this man? In most cases, the only two valid responses really are "my ISP", and "the service's hosting provider". https doesn't securize against evil hosting provider. When using Chrome+https, vs Firefox+http, in one case you give your data to your ISP, in the other case to Google. Google's primary focus is using my personal data. My ISP's primary focus is giving me Internet. Google is making fuss about https, to feed noise about Google itself. Yes, I totally agree that best is to simply Firefox https. Yes, I'm totally dismissing the issue of rogue networks. But >80% of the population uses Google, I believe that less than 20% of the population is using rogue networks. What about the issue of broken WiFi security? Well, the point stands: https is so much of a red herring, that everyone forgets to fix WiFi.
- davidmurdoch 7y agoThe man is also the hacker on the coffee shop WiFi intercepting traffic.
- bulatb 7y ago> When we say "MITM" who is this man? Anyone in `traceroute`, even indirectly. Your state. A rival state. Your ISP. Your neighbor at the coffee shop. A rogue employee at a CDN. A poisoned cache. That little thing that no one noticed in the closet. The latest malware on your router. Any of those threats on any path between the visitor and any resource on the page. > I believe that less than 20% of the population is using rogue networks. The network is hostile. Believing that it's not contributes to its insecurity: you get an architecture with a hard shell and a gooey center. One box in your "safe zone" gets popped and you're done. So make the safe zone your box and nothing else. HTTPS helps you get there. > What about the issue of broken WiFi security? What about it? Someone snooping on your WiFi can't see through your TLS. That's a reason to support HTTPS, not to dismiss it.
- johncolanduoni 7y agoI'm a bit confused as to what this has to do with Google? What advantage to they get by promoting HTTPS if all the other browsers support it as well?
- marcinzm 7y ago>My ISP's primary focus is giving me Internet No, their primary focus is to make money and they are finding that selling your data and showing you ads is profitable. Google hoards data so it can use it and I generally trust Google to keep the data secure. I don't trust my ISP to keep my data secure or not to sell it to everyone on the planet.
- captncraig 7y agoSecurity is about being paranoid in imagining what different actors can do with varying levels of access. In this case, MITM is not always easy, but once they have access they can do bad stuff. As a webmaster, an attacker with this access can break your site by messing with your users. By taking the simple step of using https, you can successfully reduce your attack surface and increase the difficulty of messing with your site.
- lioeters 7y agoIf unencrypted data in transit and an open man-in-the-middle attack vector are "definitely not a security risk", I cannot trust the author's concept of security, risk, or privacy.
- commandersaki 7y agoYet people use 3rd party VPNs that do this all the time in the guise of security & privacy.
- Wowfunhappy 7y agoI agree the author lost their argument partway through, and I would have made the point a bit differently. Broadcast TV and radio signals are not secure, and don't need to be. Their information is supposed to be available for everyone. If someone hijacks a radio station, the worst they can do is spread disinformation, and there are easier ways to accomplish that. Similarly, if all a website does is display text that is designed to be visible to everyone, a secure protocol is unnecessary. IMO, http pages which lacks input fields and other forms of two-way communication should not receive an insecure warning. By contrast, if there's an input field, there's a good chance the user expects what they're writing to be private.
- mixedCase 7y ago> the worst they can do is spread disinformation From a seemingly reputable source that people trust. Now take a 4chan prank like the home grown crystals and put it on a site like the NHS'. Grab one of the blogs of these people who post about https not being necessary and if they have any tutorial where they have terminal snippets to copy and paste you can own their reader's machines. There are so, so many ways to do mischief if not outright ruin the lives of people in these websites that "just display text".
- pixl97 7y ago>Similarly, if all a website does is display text that is designed to be visible to everyone, a secure protocol is unnecessary And how is the browser supposed to figure that out? If I can edit your data stream I can load up inline javascript that could add data submission in very hard to figure out ways. Secure protocols dont just encrypt, they authenticate the originality of the data (at least from the https instance it was sent from).
- Wowfunhappy 7y agoI should have added Javascript to the list of things http sites shouldn’t be able to do without triggering a browser warning. If it’s just a document/markup format, the warning strikes me as unnecessary. Mind, I realize that wouldn’t apply to many sites today.