4 ms·
Hmmm, why doesn't the site have https?
by lowwave 6y ago
Hmmm, why doesn't the site have https?
- Kye 6y agoThis is the late 90s and https still takes too much CPU to justify for most purposes.
- forgotmypw16 6y agoNot every browser supports current https
- oneplane 6y agoI think the author had a spat on twitter a while back because of the same question. There really isn't any excuse to not have TLS on your site, even if purely to thwart MITM injection. Most arguments are BS but still keep popping up: - heavy on the CPU (not with anything after 2006) - hard to setup (not with LE + ACME) - I don't process information (that doesn't matter/is not the reason, DPI, MITM come to mind) - browsers can't handle it (lies, browsers handle it fine, unless you're using a browser from <2010) Better yet: even if the resource/browser stuff were relevant, you can still leave http up and add https as an option.
- csixty4 6y ago> unless you're using a browser from <2010 To be fair, a lot of Jason Scott's audience is people who might choose to use ancient browsers on obsolete platforms.
- oneplane 6y agoDoesn't that make it double-bad? Again, people might come up with the argument that it's their own problem if they get abused, but also that is just not the reality we live in; any compromised system can (and will most of the time) be used to infect/compromise/attack other systems.
- anthk 6y agoGood luck trying to a attack an HTML only browser under a Z80 machine, for example.
- oneplane 6y agoWell, getting an RCE on that wouldn't be that hard I imagine. Not a whole lot of protections in there, and if there is an OS between the browser and the metal you can exploit that too. And if you don't want to exploit the browser or the hardware, you can still simply inject a self-refreshing iframe in to the plain text html stream and have that z80 act like a (slow) proxy so you can do things that will point to that Z80 being the 'origin'. Everybody assumes that 'simpler' or 'reduced' systems are always safer, but as soon as you deal with external interfaces and the outside world, that goes out the window. Lynx was thought to have less of an attack surface because it just did basic text-based browsing with HTML and not much else. Turns out that wasn't the case either.
- anthk 6y agolinks in Unix for example has automatic refreshing as a checkbox.
- oneplane 6y agoWell, then you use progressive rendering, or you use chunks, or you use something else. Sure, there might be specific mitigations that someone might have or have not set up, but that is not the point. The point is that assuming your system is safe is a bad position, and ignoring easy to use systems and processes to thwart complete classes of abuse is bad when you use a shared medium like the internet.
- lowwave 6y ago>I think the author had a spat on twitter a while back because of the same question. Ok, I guess that explains downvote to my post. I was just wondering. Cause now we can get free SSL with let's encrypt. And since traffic and be hijacked and modified, it just seems to make sense to have a site that serves text files to have ssl.
- bityard 6y agoBecause there are still plenty of valid use cases for HTTP.
- jaas 6y agoNo there aren't. All HTTP traffic can be modified, which means it can deliver any malicious payload to the server or client. It's dangerous not to use HTTPS, period.
- zozbot234 6y agoThis is silly, as the endpoint you're connecting to could also be malicious. If you're worried about trusting your intermediary, you can just VPN to a trusted host and use it as a proxy.
- neop1x 6y agoOr you can SSH to the server and read it from http://localhost http://localhost (if you have access). But there can still be malicious software running, intercepting syscalls or your localhost domain can point to a malicious IP. :/ Software can't be trusted. Period.
- tripzilch 6y agohttps://news.ycombinator.com/item?id=22997403 https://news.ycombinator.com/item?id=22997403 this comment mentions their provider inserts ads in non-https traffic.
- deleted 6y ago[deleted]