6 ms·
Fully support this argument and Mozilla's initiative. I work for a firewall co and we had taken a strategic decision to not allow plaintext traffic onto the in
by new23d 6y ago
Fully support this argument and Mozilla's initiative.
I work for a firewall co and we had taken a strategic decision to not allow plaintext traffic onto the internet (from cloud deployments). It's just lazy on the client or server operator's part to not have it so.
- cat199 6y agothis breaks caching of simple objects that do not require content security
- new23d 6y agoFrom intermediate (MITM) caches, yes. But end-clients can still cache it though. Our market is more backend API traffic so doesn't impact as much.
- wang_li 6y agoSince it's becoming harder and harder to implement transparent proxies and caches, someone should define a local cache protocol so that network administrators can configure explicit shared caches for the devices on their networks.
- jlgaddis 6y ago> someone should define a local cache protocol Someone did, almost two and a half decades ago. It's called the Internet Cache Protocol. - Internet Cache Protocol (ICP), version 2 [0] - Application of Internet Cache Protocol (ICP), version 2 [1] -- [0]: https://tools.ietf.org/html/rfc2186 https://tools.ietf.org/html/rfc2186 [1]: https://tools.ietf.org/html/rfc2187 https://tools.ietf.org/html/rfc2187
- taftster 6y agoEven "simple objects" can be MITM'd. I know I'm on the extreme theoretical edge, and so maybe your perspective is pragmatic enough to pass. But even small images, javascripts, etc. should be protected by HTTPS, not just "sensitive" pages. As an end user, I don't want the possibility of anything being tampered with along the route. As a content owner / webmaster, I want the same. So publisher and consumer are both aligned in their desire, making HTTPS ideal for everyone except for people reading/manipulating traffic along the way.
- cat199 6y agospeaking specifically of local package caches for things like onsite networks which are themselves signed OOB
- SulfurHexaFluri 6y agoThe browser can still see everything and still cache whatever it wants. Safari and likely others are turning off cross site caching anyway.
- cat199 6y agoHTTP != browser always