3 ms·
> HTTP is not ok. Anyone can ready / modify what is being sent. How do you plan demonstrate that in my local network, connection between my computer and printe
by ZWoz 4y ago
> HTTP is not ok. Anyone can ready / modify what is being sent.
How do you plan demonstrate that in my local network, connection between my computer and printer web based interface?
Generally, we had several decates HTTP as main protocol and that worked out.
- DANK_YACHT 4y agoThe underlying assumption is that we're talking about the internet, not a private network, but even your private network would benefit from encryption. What is the benefit of having anyone with access to your network potentially read / modify your network traffic?
- ZWoz 4y agoBrowsers are being pretty weak to understand difference between local networks vs internet. Lot of times I have seen hassle caused by HTTPS, be it printer or server baseboard management controller.
- cmeacham98 4y agoCitation needed. Firefox HTTPS only mode does not upgrade local IP addresses or reserved local "TLDs" like .local. If machines on your "local network" are squatting on a public IP or potentially public domain name how is the browser supposed to know the difference?
- nybble41 4y ago> Firefox HTTPS only mode does not upgrade local IP addresses or reserved local "TLDs" like .local. If machines on your "local network" are squatting on a public IP… It could be one of your public IP addresses—more likely with IPv6, but still possible with IPv4—and not simply "squatting" on someone else's assigned public IP address. The browser may not be aware that these are local. With that said, the devices should use public domain names and obtain proper certificates for them via the ACME DNS challenge, which avoids the issue altogether.
- seiferteric 4y agoAn issue I don't think is addressed is how do you get a valid certificate for a server on a local network? Like setting a new device or router, you often type in the IP address (or maybe mDN name), then you either have to use http, or for https you get a warning and have to add an exception for an invalid certificate... How would one even solve this issue on a local network? I had an idea that I was thinking would be a cool RFC, have the router run a CA, then pass a DHCP (or RA) option with a local CA certificate for the end-user device to trust. Then services could request server certs from it (via ACME protocol). The issue though is that this gives too much power to the network operator. Imagine connecting to wifi at a coffee shop and they decide to MITM your google connections...
- necovek 4y agoIf I've got a powerful enough wifi emitter, I could get close to your home and impersonate your AP using the same SSID (with open access). If you accidentally connect to it without paying attention, all unencrypted traffic is mine to record and modify. HTTPS solves that too.