4 ms·
Firefox removing support for non-encrypted data protocols makes me more confident in them, so consider me a fan of this messaging.
by ferdowsi 5y ago
Firefox removing support for non-encrypted data protocols makes me more confident in them, so consider me a fan of this messaging.
- handrous 5y agoftps exists. The solution to http wasn't getting rid of it, it was pushing for more https. I'm not saying there weren't good reasons to get rid of ftp support, but that doesn't seem like one.
- desktopninja 5y agoSurprising how many people don't know about ftps. FTP with SSL.
- floatboth 5y agoIt's very obscure. Most things (mostly shared hosting lol) went straight to SSH's SFTP instead.
- alerighi 5y agoSFTP is mainly a *NIX thing. And it's a terrible hack built on top of a protocol meant to be something really different. Also, while in theory SFTP can be as secure as FTPS, in practice it's not. How many people really check that the server public key signature it's the correct one? You know that annoying message that appears the first time you connect to a server and you have to say yes and if you don't it will not let you continue? Not checking that give you the same security as having a HTTPS/FTPS server with a self signed certificate. You trust blindly the identity of the server, but there could be someone doing a man in the middle and stealing all your data. In that situation, FTPS is more secure, mainly because you need a valid TLS certificate that will give you some guarantee about the identity of the server.
- floatboth 5y agoAt least in the pre-Let'sEncrypt era, lots of the shared hosting providers that gave you SFTP as an upgrade over plaintext FTP also used self-signed certs for their HTTPS admin panels :D Server identity keys can be checked using SSHFP DNS records signed with DNSSEC, but that is not really mainstream unfortunately.
- da_chicken 5y agoIt's because there's multiple versions which are fundamentally incompatible.
- rovr138 5y agohttp, dns, and other things are unencrypted. What would happen if they rip it out? What should be done is push for things like ftps or add big warnings around it. That wasn't the decision. Maintaining this was.
- metalliqaz 5y agothey will surely rip them out when they have fallen to the levels of usage that FTP is at now Edit: not sure why this is being downvoted... if you read the actual link, it says they intend to deprecate HTTP.
- sschueller 5y agoSo good luck configuring your firewall or NAS that don't have a valid certificate.
- acdha 5y agoSeems like a great opportunity to secure your server rather than training humans to ignore security warnings, doesn't it?
- Majromax 5y agoSecure how? Obtaining a public certificate from a well-known registrar requires Internet connectivity for the ACME protocol, and that's at odds with the other best-security-practice of isolating internal systems like NAS devices well away from general Internet connectivity. The problem is even worse for home routers. They need Internet connectivity to have a chance of obtaining a certificate, but since they provide that connectivity to a network they can't obtain the certificate until they're set up. But setup generally happens via a web browser and captive portal, so we're right in the middle of a bootstrapping problem. https/TLS everywhere on the public Internet is a great thing, but it's not a reasonable expectation for private networks with private devices.
- AstralStorm 5y agoSolved if DNSSEC is deployed and root certificates are available as they should be pinned. What, you're using old unsigned DNS and complaining about security? Or software so old that pinned certificates are outdated?
- tptacek 5y agoVirtually none of the DNS hierarchy signed with DNSSEC, and it's unlikely it ever will be. It's a strange best practice to appeal to, since it's been categorically rejected by almost every security team in the industry.
- handrous 5y ago