4 ms·
This is security hypocrisy. HTTP is a cleartext protocol. Why does your browser quietly navigate to any HTTP site you throw at it? Anonymous FTP isn't any less
by apostacy 5y ago
This is security hypocrisy.
HTTP is a cleartext protocol. Why does your browser quietly navigate to any HTTP site you throw at it? Anonymous FTP isn't any less secure than HTTP.
Why does your browser scream at you for connecting to an encrypted but unverified site, such as a self signed certificate on a closed network, but have no warnings at all for an unverified and unencrypted HTTP connection?
How do you know the context that I am using a plaintext protocol in? How do you know I'm not connecting over a patch cable to the computer next to me? How do you know I'm not connecting over an SSH tunnel?
The user should easily be able to override these safety measures.
The only argument I have heard this is that the user could be tricked into disabling security mechanisms. But that is true of anything in computing. The user could be tricked into typing in rm -rf.
When there is inconstancy like this, it usually implies there is something else going on that we aren't seeing. I have a feeling that companies like Google and Apple have an agenda to move people away from having too much outside of their influence.
- da_chicken 5y ago> HTTP is a cleartext protocol. Why does your browser quietly navigate to any HTTP site you throw at it? Anonymous FTP isn't any less secure than HTTP. This is true, but it ignores the fact that the web has been moving towards depreciation of HTTP in favor of HTTPS. While FTP is an established standard, FTPS is kind of a nightmare with different and incompatible variants.
- antisol 5y agoNo, it doesn't. The parent explicitly mentions that there are no warnings for a cleartext http connection, but warnings for an encrypted connection to a self-signed certificate. This is security theatre, not actual security.
- dvfjsdhgfv 5y ago> When there is inconstancy like this, it usually implies there is something else going on that we aren't seeing. I have a feeling that companies like Google and Apple have an agenda to move people away from having too much outside of their influence. I think it's both. For one thing, I think they genuinely do care about security, because any high-profile incident involving their products is a cause of embarrassment for them. At the same time, I have a feeling they would prefer people not inspect the traffic moving in and out of their apps, for example.