11 ms·
I wonder if this will be added to the European Spreadsheet Risk Interest Group's (EuSpRiG) horror stories list: http://www.eusprig.org/horror-stories.htm http:
by galeos 6y ago
I wonder if this will be added to the European Spreadsheet Risk Interest Group's (EuSpRiG) horror stories list:
http://www.eusprig.org/horror-stories.htm http://www.eusprig.org/horror-stories.htm
- dang 6y agoDiscussed here: https://news.ycombinator.com/item?id=22431500 https://news.ycombinator.com/item?id=22431500. (Submitted many times, but that's the only real thread, and only from 7 months ago.)
- whatatita 6y agoThe site's cert is invalid. Got a mirror?
- iso8859-1 6y agoCertificates are not applicable, the link scheme is HTTP.
- not_kurt_godel 6y agoIt presents a self-signed certificate if using a browser/extension that automatically redirects to HTTPS (which everyone should be).
- corty 6y agoIf the extension redirects to a broken cert not intended for public use, the extension is broken and should not be used. This is not making things safer, this is training users to click through warnings again. Very much "don't".
- lukeramsden 6y agoThe extension is not at fault, all it does is rewrite HTTP links to HTTPS (which should be the default IMO, I agree with the parent commenter). The fault is with the site providing a self-signed certificate when accessed over HTTPS.
- corty 6y agoAll it does is assume that a https site serves the same content and audience as the corresponding http site. That is a broken assumption. The consequences of such a broken assumption are very much the fault of the extension.
- lukeramsden 6y ago> That is a broken assumption Why is that a broken assumption? Can you name a legitimate reason for HTTP and HTTPS sites to serve separate contents and audiences? I would rather not connect over HTTP to _anything_ nowadays.
- corty 6y agoCMS, serve the content over http and the admin page over https. And for sites with noncritical static content https is superfluous to dangerous. ESNI isn't implemented yet, IP addresses are still visible to the eyes. And content sizes and timing are a dead giveaway for the things you are looking at. HTTPS for everything is just a simulation of privacy at best, and misleading and dangerous at worst, because there IS NO PRIVACY in the aforementioned cases.
- earksiinni 6y agoTIL there is something called "spreadsheet risk management." Wow. Thank you for this gem of human culture.