5 ms·
Who decides what’s non-critical? I’d prefer my news articles not be rewritten by the government for example. Catering security to the absolute lowest common den
by mcspiff 5y ago
Who decides what’s non-critical? I’d prefer my news articles not be rewritten by the government for example. Catering security to the absolute lowest common denominator (“can’t set a clock”) is not a path to success.
- forgotmypw17 5y agoSuppose the likelihood of the government or ISP rewriting my requests is very low, as it is in the U.S. Suppose also that I am an underprivileged individual whose only device is a 10-year-old tablet I happened to find in the closet. I'm searching for a crucial piece of information, e.g. how to receive a subsidy benefit or health symptoms. This is a real-world scenario I have myself witnessed, and have also read about online many times. Are you REALLY arguing for denying this human being access to the information in the name of "security"?
- ArchOversight 5y ago> Suppose the likelihood of the government or ISP rewriting my requests is very low, as it is in the U.S. Comcast used to (and maybe still does) inject JavaScript into HTTP requests when users were approaching their transfer caps, so that a warning banner would be shown to let them know they are almost at their terabyte limit. ISP's have been and continue to be caught playing tricks like this. T-Mobile for instance used to rewrite the playlists that YouTube would send down for HSL to remove the higher bitrates to reduce network traffic. Just because you are in the US does not mean you are immune from this sort of shenanigans, currently it is used mostly in the name of network management, but it could also be used for nefarious purposes. I also fully believe this is why public libraries should exist. The library near me has new computers, help that can help the person navigate those sites and even has tablets available for loan.
- forgotmypw17 5y agoSo, you have a choice between: ISP may inject bandwidth cap limit -or- No access to information at all What do you think the person looking for critical information would choose? By the way, libraries are scarce in the U.S., and library computers have been some of the most out-of-date and poorly maintained machines I've used. This is a problem I have no chance of solving, while allowing HTTP access is something I can do today.
- Dylan16807 5y agoYou act like "no access" can't happen because other things break. If that was the only choice, I'd consider it, but I'm not going to give up everything in tiny incremental bits to maximize access in every edge case. Also you could disable expiration as a much safer measure.
- forgotmypw17 5y agoThere are many reasons something can break. I'm not sure how you got the impression I believe otherwise. There are many reasons someone may not be able to access. Furthermore, some of those reasons can be known ahead of time, and some cannot even be predicted before they happen. But the ones I do know of, I try to accommodate, just like i try to accommodate visually impaired, those with slow devices, etc. And I have found that the more known scenarios I accommodate, the more unknown scenarios are also accommodated, just from raising the accessibility bar. Of course, this is not something everyone cares about. You probably won't gain many profitable customers with deep pockets accommodating the edge cases. They're all using the latest and greatest. But if you care about allowing access to as many as possible to your resource, serving both HTTP and HTTPS is the way.
- Dylan16807 5y ago> I'm not sure how you got the impression I believe otherwise. It's the impression your post gives. Either I pick insecurity -or- it breaks. The real version is I pick insecurity -or- the number of ways it can break goes from 73 to 74. And I care about accessibility too. That doesn't mean I indiscriminately want to increase access. The downsides of certain methods are important.
- CamperBob2 5y agoI decide what's non-critical. What a concept, huh. If I consider an online transaction to be critical, I'll check for https:// https:// in the address bar. Usually I don't. Case in point: Firefox 93 now issues gratuitous scary warnings when a .PDF is downloaded over a non-https connection. [1] Right now it only seems to happen if you arrive at the link via a search engine, but it would be silly to pretend they'll stop there. There is nothing OK about this. It literally breaks the whole idea of decentralized Internet protocols. The obsession with "https everywhere" needs to stop, now. Otherwise, not only will our future landfills groan under the weight of megatons of e-waste that didn't need to stop working when it did, but our collective cultural history online will eventually consist of nothing but undecodable random numbers. Not everything needs unbreakable encryption. The vast majority of online content doesn't. 1: https://i.imgur.com/NwXeyGx.png https://i.imgur.com/NwXeyGx.png
- yjftsjthsd-h 5y ago> The obsession with "https everywhere" needs to stop, now. Otherwise, not only will our future landfills groan under the weight of megatons of e-waste that didn't need to stop working when it did, but our collective cultural history online will eventually consist of nothing but undecodable random numbers. If those devices can't even update certs, they absolutely should not be online because they're solid blocks of vulnerable software that will just contribute to botnets. And the only way for this to contribute to losing history is if you're somehow archiving content by grabbing it off the wire, which seems inefficient anyways.
- CamperBob2 5y agoIf those devices can't even update certs, they absolutely should not be online because they're solid blocks of vulnerable software that will just contribute to botnets. Ah, yes, the presumption of guilt. "You're going to do a bad thing at some point, I just know it. This is probably because you're a moron, while I'm not. Fortunately, I have the solution." We hear that a lot these days.
- nonameiguess 5y agoI don't see how this kind of argument generalizes. Short of armored truck deliveries, cryptographically signed digital transmissions are about the only form of information delivery where it's even possible to get this kind of assurance. Yet civilizations have operated for centuries if not millennia on the premise that we deliver things nonetheless. There is no guarantee at all that the government isn't rewriting the New York Times before it hits newsstands, intercepting and changing television signals, swapping out or reading your mail, injecting mind control serum into foods before they reach the grocery store, or that fluoride isn't used to subdue the population (other than science, but you don't know the government isn't intercepting and rewriting published research). The only assurance you get is all these things are illegal. Governments definitely don't universally follow their own laws, but at some point, the existence of some system of laws is either enough for you, or you go live in the woods with a bunker full of seeds and ammo, or start a revolution to replace the government with a new one.