5 ms·
The reason to do it is because while HTTPS is not perfect (especially when it comes to certificates), the attacks against unencrypted and unauthenticated plain
by MrRadar 6y ago
The reason to do it is because while HTTPS is not perfect (especially when it comes to certificates), the attacks against unencrypted and unauthenticated plaintext HTTP (as I outlined in my other post) are incredibly trivial in comparison. The main point of HTTPS-only is to make the attacks significantly harder and more costly to execute and easier to detect when they do happen. We cannot let the perfect be the enemy of the good. Are you comfortable with ISPs injecting ads into your blog? [1][2]
> FWIW, my phone is 10 years old.
I'm curious, which phone is this and what do you use it for?
The oldest phones I keep in somewhat regular use are a Moto X (8 years old) and a Moto E (6 years old) which I maintain service on using free service providers (which require I use their service at least once each month or my service will be discontinued). When I turn those phones on each month to place a call with them, they take at least an hour to download and install app updates before I can even start using them. On the Moto E I've had to uninstall most apps because the internal storage has been nearly exhausted just by installing the latest updates for the bundled apps. On both phones even just bringing up the keyboard after I select a text field takes multiple seconds and any kind of multitasking is out of the question. I could not imagine trying to use either of those phones on a daily basis.
[1] https://arstechnica.com/tech-policy/2013/04/how-a-banner-ad-for-hs-ok/ https://arstechnica.com/tech-policy/2013/04/how-a-banner-ad-...
[2] https://www.reddit.com/r/india/comments/8ry1k4/does_your_isp_inject_malware_ads_in_the_websites/ https://www.reddit.com/r/india/comments/8ry1k4/does_your_isp...
- eesmith 6y agoI read https://news.ycombinator.com/item?id=25825188 https://news.ycombinator.com/item?id=25825188 but didn't understand how the threat models apply. > Firstly it prevents MITM attacks that inject Javascript (or other) payloads into web pages which can be used e.g. for DDoS attacks If someone nefarious wanted to MITM my web site, the easiest would be to spoof DNS so it went to some other host, and do the MITM that way. Your ISP could do that to you, no? While more people could spoof the http connection than spoof the DNS, what's the threat model? If it's the Great Firewall then all users behind it are also using their DNS. Which is why (as I understand it) you also need things like 'integrity' in your links in order to avoid the attack you describe. Not simply switching to https. > Are you comfortable with ISPs injecting ads into your blog? [1][2] They aren't injecting ads into my blog. They are injecting ads into your transfer of files from my site. Why are you using an ISP which does that? > You can still track which sites a user connects to, but you can't see which pages they access or the contents of those pages Again, what's the threat model? I'm pretty sure simple traffic analysis would be enough to figure out, based on download size and number of additional requests made, which pages are downloaded. While there are ways to mitigate that, it's not as simple as moving to https to prevent anyone from figuring out what my users are accessing on my site. So, do I give my users a false sense of security by switching to https? It depends on the threat model, doesn't it? > I'm curious, which phone is this and what do you use it for? Does it make a difference? It's meant to underline the point I made that not everyone has new hardware. The question for you is, how many people and devices will I block by switching to https-only? Will poor people using second-hand computers be able to access things? Will old Docker images with scientific projects on them stop working when the embedded certs age out? I have an implicit promise that if you could access URL X using method Y then you will always be able to access URL X using method Y. Why should I break that promise. To be sure, I also have a site behind https. Among other things, it serves pip-installable packages. Which is why different threat model than my static blog site. (It also doesn't have the a 20 year old implicit promise.)
- MrRadar 6y ago> If someone nefarious wanted to MITM my web site, the easiest would be to spoof DNS so it went to some other host, and do the MITM that way. Your ISP could do that to you, no? That's what certificates are for. While certificate authorities can also be compromised, most ISPs don't run their own so they'd have to get a separate organization to cooperate with them to do this. > They aren't injecting ads into my blog. They are injecting ads into your transfer of files from my site. Why are you using an ISP which does that? This seems like a very strange semantic argument. From the customer's point of view they are injecting ads into your blog. Many people are not technically-savvy enough to understand that it's the ISP that's putting the ads in and not you. And for many people in the US and I'm sure also around the world they may not have a choice in ISP for a given level of service (would you choose dial-up or satellite over broadband if the only broadband provider that serves your area injects ads on non-secured pages?). > Again, what's the threat model? I'm pretty sure simple traffic analysis would be enough to figure out, based on download size and number of additional requests made, which pages are downloaded. The threat model is pervasive passive surveillance. The IETF recognizes this: https://tools.ietf.org/html/rfc7258 https://tools.ietf.org/html/rfc7258 HTTPS greatly increases the costs of such surveillance (you can no longer just look at the bytes on the wire, you need to closely examine the site the user is connecting to to correlate the amount of data transferred with specific pages on the site; for dynamic sites or sites using HTTP/2 this can be much harder). > Does it make a difference? Not to my argument, but I was genuinely curious what 10-year old phone anyone can consider usable today and the use-cases they have that still accommodate such old hardware. (I could see a basic non-smart phone still being useful, as long as the networks it supports are still active (which in the US will probably not be for more than another year or two)).
- eesmith 6y ago"That's what certificates are for" Could you explain that? I thought that if DNS were spoofed then people could be redirected anywhere else, no matter what the certificate said. I thought that could be mitigated by CAA records, but that too could be spoofed, eg, by your service provider. How do I prevent the government of China from MITM-ing access to my web site from someone in China, using a Chinese mobile phone with certificates pre-installed and automatically by the local Chinese telco? "This seems like a very strange semantic argument" I think you're making the strange argument. If I get a "free" cell phone which has a modified browser that inserted ads when viewing my web site, then from the customer's view those ads are on my site, right? But of course there's nothing I can do about that. Nor can you. So why place the responsibility on me? "if the only broadband provider that serves your area injects ads on non-secured pages" Have you not seen all of the ads for systems like SecureVPN? "pervasive passive surveillance" One of the pervasive passive surveillance attacks mentioned in the ietf link is traffic analysis, which I mentioned earlier. Can you guarantee that if I simply switch to https then the NSA could not use traffic analysis to figure out what users access from my static-pages, public-facing web site? Do you seriously think the NSA hasn't automated something as simple as remembering download sizes for each page, for a large number of web sites, in order to infer things like this? So do my readers gain any additional security against NSA surveillance by switching to https? Don't forget that my service provider (in the US) can be forced to reveal details and do tracing without telling me, including providing clear-text access to the logs. Since I cannot defend against NSA surveillance on my readers, I have to choose a threat model where I can make a difference. And I can't figure out who I should care to thwart, where https would make a meaningful difference. Clearly there are web providers which can and should use https to protect privacy against non-nation-state actors. Passwords, money, and the ability to insert code without review are three things which change the balance. But I don't see any benefit for my basic blog site that's been around for 20 years, and there appears to be a (small?) negative.