4 ms·
could prob do with a HTTPS redirect tho :p and maybe a sprinkling of HSTS
by cottsak 6y ago
could prob do with a HTTPS redirect tho :p and maybe a sprinkling of HSTS
- whirlwin 6y agoYeah. Quite funny. "Do as I say, not as I do".
- alanfranz 6y agoWow, I don't know if it's intentional on the part of the authors, but, on the contrary, I'd ask you: why? What is your threat model? Do you think somebody may perform a MitM to replace the information on the website? Do you think somebody could sniff your communications with that website and there could be any negative consequence for any party? The HTTPS movement, in a lot of situations, suffers from non-threat modeling issue. There's very little gain from https-protecting a page like the linked one; at the same time it's true that the cost involved is minimal.
- goalieca 6y agoMy old isp used to inject ads and other warnings into plain http traffic. I think it’s generally considered a good posture to be defensive and have privacy as default. Time has shown that information is power no matter how boring you think it is.
- beermonster 6y agoAside from helping mitigate MiTM, https has other benefits - Faster due to that fact HTTP/2 can be used. - Makes censorship harder as individual pages cannot be censored but rather the entire site which is more noticeable - Stops ISPs injecting content/tracking - Stops transparent proxies injecting content/tracking - Helps with page ranking as search engines prefer sites which load faster and offer improved security - Mixed content is a bit of a headache, with external resources such as JavaScript being loaded and leading to browser warnings.
- alanfranz 6y agoYes, these are a lot of valid reasons. My point is that the GP did NOT threatmodel, and instead claimed a vague "I want HTTPS". HTTPS is so easy to do now (and, hey, the manifesto page offers an https version indeed, it's just not HSTS enabled) that there're few reasons not to use it. But still: you should threat model.
- mac-chaffee 6y agoJust two weeks ago, security researchers (like the kind of people who would be interested in visiting this page) were targeted by hackers which used a still-unpatched (as far as we know) Chrome zero-day to install malware: https://blog.google/threat-analysis-group/new-campaign-targeting-security-researchers/ https://blog.google/threat-analysis-group/new-campaign-targe... If this page started getting popular, a MitM attack to inject malware is a very real possibility.
- 2112 6y agoOn a large number of high value targets. Like this : http://dirk-loss.de/ssh-port-forwarding.htm http://dirk-loss.de/ssh-port-forwarding.htm In the "A visual guide to SSH tunnels" thread. Not saying it's compromised, but why would fully security conscious people, experts even, not have https:// https:// enabled ? Sounds sketchy as f** to me. > If this page started getting popular ... HN frontpage is about as good as it gets I think. https://addons.mozilla.org/en-US/firefox/addon/https-everywhere/ https://addons.mozilla.org/en-US/firefox/addon/https-everywh... -> will save you from a lazy click on a non-https link. Isn't it the case though that many malicious sites have https:// https:// enabled ?
- 2112 6y agoFrom the link you provided ; > In each of these cases, the researchers have followed a link on Twitter to a write-up hosted on blog.br0vvnn[.]io, and shortly thereafter, a malicious service was installed on the researcher’s system and an in-memory backdoor would begin beaconing to an actor-owned command and control server. At the time of these visits, the victim systems were running fully patched and up-to-date Windows 10 and Chrome browser versions. Like seriously ? Security researchers run Windows 10 and Chrome ? I mean if that's their testing environment I get it, but this sounds like they legit use that in the wild and click funny links sent to them from people claiming to be fellow hackers ? Outsider here, but is that really how it is ? I would think they use hardened OSes and !Chrome ...
- nokya 6y ago"There's very little gain from https-protecting a page like the linked one." - malicious content injection - malicious content injection - malicious content injection - and... malicious content injection. Four valid reasons.