14 ms·
Increasing HTTPS Adoption
- yoursunny 5y agoI hope HTTPS-First mode would become the default, so that the full page warning can finally convince my classmate to adopt HTTPS on their website that "does not contain any private info so it doesn't need encryption".
- marcellus23 5y agoIs it a web app or just a static site? I still haven't seen a good argument for why static sites (blogs, personal sites, etc. that process no user information) should implement HTTPS.
- jefftk 5y agoDo you want ISPs or other intermediaries to be able to inject ads into static sites?
- machello13 5y agoNo, but if that's the only benefit, I'll happy give that up in exchange for not having to deal with HTTPS.
- badsectoracula 5y agoWhy is this something the sites have to care about? This is an issue to take with your ISP.
- Seirdy 5y agoDo you think a complaint from all three customers in your area who understand the issue is going to change anything, especially when options are limited and your only choices of ISP are engaging in the same behavior? On unencrypted connections, there's nothing preventing an intermediary from altering a page. Assume it happens.
- badsectoracula 5y agoA complain by three people wouldn't make much but if it is just three people in an entire country then the issue doesn't matter much in the first place. On the other hand, a complain by all the customers of the service over the entire country who understand the issue could make a difference.
- jefftk 5y agoMy ISP is fine. But no way am I going to let anyone who happens to be upstream of my visitors make arbitrary changes to my site!
- soheil 5y agoWhat makes you think HTTPS is going to prevent that? You can without much effort generate your own SSL certificate and MITM attack HTTPS traffic [0]. Not sure why to win an argument you stop short of the place where your argument would fall far apart, but not a single step further. https://www.charlesproxy.com/documentation/proxying/ssl-proxying/ https://www.charlesproxy.com/documentation/proxying/ssl-prox...
- MrRadar 5y agoOf course you can MITM HTTPS if you get the end user to install a custom CA, the point is that those are extra steps that few users will take (and if my ISP ever required that I would switch to a different one immediately since that's shady as hell).
- soheil 5y agoAnd how prevalent is the practice of ISPs injecting packets into non-HTTPS traffic? Seams like OP is trying to argue against HTTP just because of a few ISP bad actors. HTTP is simpler, faster, less complex and requires much less initial configuration to set up. It also seems to me that HTTPS would be a great way for an evil tech monopoly (Google?) to solve the user attribution problem much more accurately in a cookie-less world (if you control the browser "Chrome" and the server "AMP" you just need to make sure the link between the two is encrypted to identify the user.) So I'm always worried whether opponents of HTTP have not been somewhat indoctrinated.
- Seirdy 5y ago> And how prevalent is the practice of ISPs injecting packets into non-HTTPS traffic? Is there anything preventing page alteration on unencrypted connections? There's certainly an incentive to do so.
- kmeisthax 5y agoExcluding things like zero-day exploits, the biggest problem with allowing any unencrypted traffic is cache-poisoning. This was noticed when a Google engineer went on holiday, and stayed at a hotel with dodgy Wi-Fi that copypasted ad scripts into anything that looked like jQuery. Said engineer realized that his laptop was still getting hit with the hotel's ads for months afterwards, because it had managed to poison one of those "JavaScript CDNs" that a lot of other sites use. This is, of course, an attack - a hotel that can get an ad script onto arbitrary sites by rewriting one unencrypted request can also add a script that, say, siphons information off of any other site it got included into.
- r1ch 5y agoThankfully the impact of this is limited in modern browsers as the cache is partitioned by site.
- kmeisthax 5y agoWhich, incidentally, also removes the last fringe benefit of those free "JavaScript CDN" services. They are a strict net-negative now.
- Ajedi32 5y agoSounds like Chrome is finally taking steps to combat that, as the post mentions they plan to "Restrict how, and for how long, Chrome stores site content provided over insecure connections" PoisonTap is a particularly good example of how devastating this type of attack can be: https://github.com/samyk/poisontap https://github.com/samyk/poisontap
- geofft 5y agoI use HTTPS on my blog, which is a static website with no comments, because my blog contains information that I want people to be able to trust, and so I don't want an MITM to be able to modify it. There are a whole bunch of says that they can do that. The obvious way is that a lot of my blog is about programming, and so I have code on my blog people can copy/paste. If a MITM can modify that (perhaps by injecting something with font-size-zero), that directly harms my readers, and selfishly, that reflects poorly on me - it makes it look like I'm trying to harm my readers. I also have prose blog posts where I express advice or opinions. If I write about, say, security advice, and that advice has been modified to be bad, that also harms my readers and reflects poorly on me. Why would someone do that? I don't know, there are lots of trolls on the internet. More interestingly, I also write about my religious beliefs. If someone modifies a post to make me look like I'm one of the most egregiously bigoted people of my religion, that would also be harmful to my readers and reflect poorly on me, and the casual reader might not notice that the post is out of character, and there are a lot of people on the internet who are angry at my religion. Also, even if I didn't have any such information, a MITM could add a cryptominer or something to my blog - something that accesses no private information but still consumes my visitors' CPU and battery - would harm my readers and reflect poorly on me.
- a1371 5y agoAs a whole https makes internet better for sure, but what's wrong with the classmate's argument in particular?
- kevincox 5y ago- It is still revealing what content you browse. For example your ISP may be profiling you. (There are other leaks that reveal the domain to the ISP but hopefully those are slowly being removed as well). - A man-in-the-middle may replace your innocent content with something unpleasant. This is both bad for the viewer, and harms your reputation (even if it wasn't your fault).
- josefx 5y agoThe good old malware.cx is completely secure and trustworthy as long as it has a https cert warning.
- flowerlad 5y agoWhat is sorely lacking today is an encryption solution for the intranet. When you are transferring confidential data (such as salary info) over the network in intranet situation we need to encrypt the information to prevent casual snooping using tools such as Wireshark. We don't need to verify the identity of the server because that's typically not a problem on the intranet. Self-signed certificates used to be the solution in this situation. But browser makers have made it significantly harder, if not impossible to use self-signed certificates, by not allowing the user to visit sites that have self-signed certificates. We need a simple solution for this -- a solution that works even for small businesses that do not have an IT department. (That means installing certificates on each end-user's machine is not a reasonable solution.)
- ryandrake 5y ago> We don't need to verify the identity of the server because that's typically not a problem on the intranet. Sorry, not a security expert. What is the point of encrypting if you're not also sure you're sending the encrypted data to the right entity?
- gruez 5y agoIt helps against passive observers. This might not be very important over wired, but on WPA-PSK setups, knowing the network password allows you to eavesdrop on communications by any of the computers.
- staticassertion 5y agoWhy would an attacker in your intranet who's looking at your network traffic be passive? When people talk about passive attackers they're talking about the NSA/ your ISP, not someone who's hands-on-keyboard sniffing traffic. There's virtually no reason to do encryption without authentication in your intranet.
- spijdar 5y agoEncryption without signing is arguably more useful than not encrypting at all, although there's an argument that non-signed encryption gives a false sense of security that encourages bad practice. However, > we need to encrypt the information to prevent casual snooping using tools such as Wireshark. Given this goal, signing is necessary. If you're not signing the encryption, you can use a tool like Wireshark combined with Bettercap to man-in-the-middle the encrypted session, and there's no point.
- pupppet 5y ago> In particular, our research indicates that users often associate this icon with a site being trustworthy, when in fact it's only the connection that's secure. Never really thought about that, but I guess it's pretty obvious. I can totally see my folks downloading/buying god-knows-what from a site because they see that lock icon.
- cunthorpe 5y agoThey started realizing this when HTTPS was becoming common thanks to Let’s Encrypt and slowly started removing any greenness and “Secure” label from the URL bar in favor of doing the opposite: marking insecure websites in red. This last change is obvious and needed but was probably left as a last step because people have been taught to look for it at some point. Glad to see it gone, even just ‘cause Safari puts it in the middle of the URL bar and I keep clicking on it by mistake. Hopefully they’ll drop it to by 2024
- corentin88 5y agoRemoving the lock icon is a very good idea. I’m not surprised that Chrome’s team found out that only 11% of participants to a survey understood what it really means.
- izzytcp 5y agoThat means they should wait until 90% of them know what it means, before removing it.
- kevincox 5y agoI don't see the logic here.
- notatoad 5y agonot only is removing the lock icon a good idea, replacing it with a dropdown indicator is a great idea. there's all kinds of useful stuff in that menu, currently hidden behind something that looks like a status indicator rather than an interactive element.
- mgarciaisaia 5y ago> In particular, our research indicates that users often associate this icon with a site being trustworthy, when in fact it's only the connection that's secure. I had the idea that browsers were showing a grayed-down padlock for standard HTTPS certificates (ie, "connection is encrypted") vs a full-blown green icon with the company name next to it for the HTTPS certificates that also validate identity (DV? EV? I don't recall the meanings and acronyms). I guess that's where we should go now: make HTTPs the default (thus showing a standard icon that doesn't call for any attention), a big red ugly icon alerting non-encrypted connections, and a green one with identity attached meaning you can indeed trust this particular site to really be your bank.
- forty 5y agoI think most browsers have stopped displaying EV certificates differently for a while.
- nightpool 5y agoYes, the goal was that EV certificates would fill this gap. However, research showed that they didn't meaningfully affect user behavior[1], it was easy to get CAs to issue EV certs for company names that misled the user into thinking the phishing site was secure[2], and it was even possible to issue colliding EV certificates simply by registering your company in a different jurisdiction[3]. So in 2019, Chrome, Safari and Firefox all removed the "special" treatment of EV certificates. (In Safari it's still distinguished by a green vs grey lock icon, I believe) [1] https://chromium.googlesource.com/chromium/src/+/HEAD/docs/security/ev-to-page-info.md https://chromium.googlesource.com/chromium/src/+/HEAD/docs/s... [2] https://typewritten-archive.cynthia.re/writer/ev-phishing/ https://typewritten-archive.cynthia.re/writer/ev-phishing/ [3] https://arstechnica.com/information-technology/2017/12/nope-this-isnt-the-https-validated-stripe-website-you-think-it-is/ https://arstechnica.com/information-technology/2017/12/nope-...
- tialaramex 5y agoAlso, this feature (EV certificates) exists because the CAs wanted to sell a product with a higher ticket price, and it shouldn't be mistaken for something engineers designed to actually deliver any security. For example, suppose you go to https://som.example/ https://som.example/ which is the web site for "Somex Ample" products. You don't trust "mere" DV certificates for som.example, which you believe may be purchased by bad guys, but you're comfortable because "Somex" has purchased an expensive EV certificate for "Somex Ample" of Springfield. You fill out a form on the secure web page, and hit submit. But, unlike you, your web browser intentionally has no idea who "Somex Ample" are and no interest in whether they spent a lot of money on their certificate. When the server it reaches has a boring DV certificate for som.example that's fine, the browser compares this name to the name in the HTTPS URL and it matches exactly so that's fine. The browser sends your form data to this server, gets back a 30x redirect and then (maybe after some more bounces) gets a fresh web page to show you. This page might come with one of those shiny EV certificates you like, or it might not. Either way, that form data you were careful to only fill out on the "safe" EV page, went to a server without an EV certificate. So, getting rid of the separate UI indication for EV was largely reflecting a reality that already existed. The DNS name is correct because the browser always verifies that matches at every step, but if you're relying on something else it's on you.
- jasonkester 5y agoCan anybody suggest what might be the motivation for this? Beyond the silly "bad people might tamper with the cat picture you're shown" one that is always given? Chrome hates http with such a passion that there must be some evil motive behind it that I'm not seeing. Because they just keep making life more difficult for websites that don't need SSL. So now in addition to seeing a scary icon on the url bar with a scary message, my users are going to have to click past an interstitial banner just so they can visit a website and read silly travel stories. Chromium will try their best to convince them to leave, lest some nefarious agency on their home wifi substitute alternate silly travel stories that somehow cause them harm. In the 20 years the site has been live, I skeptical that this has happened often enough that we need to get Google involved. It's frustrating.
- johnnyapol 5y agoI don't know Google's motivation but frankly I welcome TLS everywhere on the public-facing web now that certs are free thanks to LetsEncrypt. For me, it comes down to two things: 1. Privacy. When I'm on non-private networks, its nice to have assurance that other people aren't able to get the specific contents of what I'm viewing. 2. ISP bad behavior. A number of ISPs have been doing things like injecting ads or other trackers into plain-HTTP sites. https://www.infoworld.com/article/2925839/code-injection-new-low-isps.html https://www.infoworld.com/article/2925839/code-injection-new...
- inshadows 5y agoHopefully, LetsEncrypt is and will always be incorruptible organization. There was never a case of a community project being taken over by greedy capitalists. Oh wait...
- remram 5y agoThere are a lot of safeguards like certificate transparency logs. They would be caught.
- johnnyapol 5y ago
- litoE 5y agoMy home network includes a router and several WiFi access points. They are managed through a browser, which means they have a built-in web server. I have them configured so they are only visible from the internal IP addresses and changed usernames and passwords from the built-in defaults, but there's no way to install a certificate in them, let alone force them to use https. So whenever I use Chrome to reconfigure one of these devices I get warnings of impending doom. A big PITA.
- foobarbazetc 5y agoI know it's just another test, but the constant changes to the lock icon/indicators that a connection is secure are becoming annoying...
- jeffbee 5y agoInteresting that "Linux" is the platform with the lowest observed adoption of HTTPS ... implies some kind of bias in the way Linux users use Chrome. ChromeOS, which is also Linux but I assume not included in the data with the Linux label, has by far the highest fraction of HTTPS.
- tialaramex 5y agoI assume it's mostly Devices and Servers. You probably visit the HTTPS site for Big Electronics Co. but your Big Electronics Co. "smart" television uses HTTP for the same reason it added a slow, clunky "Welcome" page with video adverts - you are a victim not a customer. The type of server software developer who years ago searched Stack Overflow for how to "fix" the problem of certificate errors, now just uses the plaintext HTTP calls where possible, and thus avoids needing to "fix" the problem by not having any security. And there's a bunch of completely automated stuff that genuinely does need plaintext HTTP on purpose. OCSP requests, for example, are plaintext HTTP. When you realise what they're for this is obvious, if I need an OCSP check to do HTTPS, but I need HTTPS to do an OCSP check, then I have infinite recursion.
- beefman 5y agoI don't understand the holy war against http. Let those who want https use it. Forcing the additional friction of certificates on every site and use case is dumb. Not even touching on the fundamentally flawed trust model behind https, here's a sample of recent stories about expired certificates: https://news.ycombinator.com/item?id=25132182 https://news.ycombinator.com/item?id=25132182 https://news.ycombinator.com/item?id=24237400 https://news.ycombinator.com/item?id=24237400 https://news.ycombinator.com/item?id=24187920 https://news.ycombinator.com/item?id=24187920 https://news.ycombinator.com/item?id=22227266 https://news.ycombinator.com/item?id=22227266 https://news.ycombinator.com/item?id=18649932 https://news.ycombinator.com/item?id=18649932 https://news.ycombinator.com/item?id=16541235 https://news.ycombinator.com/item?id=16541235
- spartanatreyu 5y ago1. Can you give a use case for a website that needs no security what so ever? 2. Don't. Your web host should be doing it for you.
- netr0ute 5y ago> 1. Can you give a use case for a website that needs no security what so ever? http://neverssl.com http://neverssl.com
- tialaramex 5y agoBut, when was the last time you needed that? My phone and my laptops both seem to correctly notice (via services for the purpose) when there isn't proper Internet access and give me access to some awful Captive Portal to fix that, for which they do not need neverssl.com. This desktop never leaves my home, which doesn't have any such nonsense. The services they use to do that do involve plaintext HTTP, but importantly they aren't trying to just be something you type into a web browser, and so aren't affected by automatic upgrades of stuff you type into a web browser.
- iso1631 5y ago
- tyingq 5y agoNo mention of ECH (Encrypted Client Hello). Current status: https://www.chromestatus.com/feature/6196703843581952 https://www.chromestatus.com/feature/6196703843581952
- deleted 5y ago[deleted]
- tialaramex 5y agoECH is still under development. Draft 12 https://datatracker.ietf.org/doc/html/draft-ietf-tls-esni-12 https://datatracker.ietf.org/doc/html/draft-ietf-tls-esni-12 is like a week old.
- tyingq 5y agoYes, though Firefox has support for it now, so current status is still interesting.
- gerdesj 5y agoThe "hit piss" (https) first thing is all very well but there are times when "hit pip" (http) is fine. You don't generally use an Enigma machine at home. We generally live in a RFC1918 n stuff world which describes "internal" and "external". IPv6 focusses the boundary between you and me in a different way. Why should my browser decide what I do on my own home network? Why should a mere tool pontificate about stuff that I know more about than the kids who developed it? Fine, I should probably develop my own browser in ASM but I don't speak nonsense. I sort of know what a processor register is but it would probably bully me. I am increasingly seeing top down decisions from monstrously huge corporations "for my own good" and I am increasingly getting worried. I rant at my elected government officials because that is what they are for (I don't really) but commercial corps are increasingly insinuating themselves into important discussions and their moral stance is undecipherable.
- userbinator 5y ago100% agree. These authoritarian corporations are out to "secure" their control over the population, squeezing and herding them however they want. It's particularly telling when the most downvoted comments contain the most truth.
- UncleMeat 5y ago> Why should a mere tool pontificate about stuff that I know more about than the kids who developed it? The decision might not be for your own good specifically, but ultimately the defaults affect 1B+ people. And the huge majority of those people do not understand many of the words that are in you post. You are an outlier and that will mean that product decisions will often not be focused at you.
- WalterGR 5y agoHas anyone found scheduling information about this? When can we expect this in Chrome, for example? Edit: Oh, here we go: https://chromiumdash.appspot.com/schedule https://chromiumdash.appspot.com/schedule This is for Chromium and not Chrome, though: ... Feature Freeze Thu, Jul 29, 2021 ... Stable Cut * Tue, Sep 14, 2021 Stable Release Tue, Sep 21, 2021 ...
- bullen 5y agoHTTPS is not secure if someone has a root cert and wastes energy, if you need encryption you should roll your own. I used https://datatracker.ietf.org/doc/html/rfc2289 https://datatracker.ietf.org/doc/html/rfc2289 for login which is simpler and uses less energy than public/private key encryption and quantum safe out of the box. Google of course has a root cert and is making sure less people can make web sites by building more protocol extensions that the average joe can afford to keep up with. I expect to be severly down voted but it's ok, I'm used to it by this point. Truth is always downvoted by vested interests to higher degree than average joes are willing to upvote it.
- chousuke 5y agoInstead of just making the claims above, can you demonstrate with examples or evidence that they are true? I'm somewhat concerned about the state of matters myself, but why and how is it that you think Google is making website creation less accessible? Your comment would have been fine without the last bit, albeit light on justification for your position to make the arguments. Attempting to guilt-trip people that you want to reach is not an effective strategy, and potentially getting downvoted does not validate your position.
- bullen 5y agoThe police station in Stockholm can read visitors HTTPS traffic over their WiFi in clear text and they show it to you when you are there. They simply substitute their root cert and your browser behaves like normal only they can decrypt your HTTPS traffic. Certificates are a bamboozle of power (who/why/how some entity gets a root cert) and the waste they involve is simply not worth it. --- - HTTP/2 has head of line issues = it's not better than HTTP/1.1. - HTTP/3 has adoption issues and ossification of a protocol is THE feature. - WebSockets are a similar ordeal. I use HTTP/1.1 Comet Stream and it works very well, it's simpler and can scale "joint parallel" on multiple cores. --- I'm a bit weary that after 5 years of telling HN to force comment upon downvote nothing has happened. Your downvote needs to be official otherwise it's unclear who thinks what. Eventually the HN database will leak and then it will be pretty clear who has downvoted what, so it's only a matter of time anyway.
- BrandoElFollito 5y agoHTTPS is complicated. python -m http.server → you have a web server that you can use for ad-hoc needs. Coding TLS into a web framework is hard. Ah, I should use a proxy? So installing a TLS on a proxy is hard. Ah, I should use caddy with LE? Sure (I use it for years), now how do I do that for 10.2.3.10? I understand why HTTPS is useful (to encrypt your traffic, certainly not "to know you are on the right server"), but it is a failure form the start - usability-wise.