4 ms·
Thank you for this. The Love of Complexity is Real in this field. While I encourage and support the goals of anonymity and security everywhere, everything has i
by mindless_solips 5y ago
Thank you for this. The Love of Complexity is Real in this field. While I encourage and support the goals of anonymity and security everywhere, everything has its design envelope.
This is an e-zine of public content. Sure, "SoMeOnE cOuLd InTeRcEpT", but why bother? Even with encrypted sockets, logs would still show your IP going to the site. What information are we trying to protect or malicious activity are we trying to stop by using SSL?
... And is it worth the unfortunate webmasters having to deal with bullshit like LetsEncrypt's root certificate expiration and all the main of keystores and PKI management so random "Very Serious People on the Internet" can say "ah, they follow The Standard on security."
Controversial statement in 2021, I'm sure, but I think a use case for simple HTML over HTTP websites still exists. Your personal page with pictures of cats and your resume probably doesn't need to be some bastion of cybersecurity.
- frankjr 5y agoThere are ISPs that will happily inject ads and tracking codes into pages you visit. This obviously doesn't work over HTTPS. https://security.stackexchange.com/questions/157828/my-isp-bsnl-india-is-injecting-ads-using-phozeca-which-spoils-websites-and-mak https://security.stackexchange.com/questions/157828/my-isp-b... https://superuser.com/questions/902635/isp-is-inserting-ads-into-web-pages https://superuser.com/questions/902635/isp-is-inserting-ads-... https://old.reddit.com/r/india/comments/8ry1k4/does_your_isp_inject_malware_ads_in_the_websites/ https://old.reddit.com/r/india/comments/8ry1k4/does_your_isp...
- jart 5y agoEven with HTTPS ad injection is still very common and it's not just happening in India. Even laptops sold here in America by big reputable brands have been known to preinstall things like layered service providers that proxy deciphered ssl communications through a server in a foreign country that injects ads. https://ag.nv.gov/uploadedfiles/agnvgov/Content/News/PR/PR_Docs/2017/2017-09-05_Lenovo_Complaint.pdf https://ag.nv.gov/uploadedfiles/agnvgov/Content/News/PR/PR_D...
- mindless_solips 5y agoWhat an incredible link and story I hadn't heard of at all. Reading that Lenovo literally knowingly installed self-signed certs on their laptops to send encrypted traffic to ad bots is one of the more horrifying device manufacturer findings I've ever seen.
- xorcist 5y agoOf course it does. You just have to install their certificate. Whole countries engage in this.
- frankjr 5y agoI mean, if you go out of your way to bork the system then yeah, I suppose it does.