7 ms·
Do you really want your ISP to know which piracy sites you frequent? This is all being sent in plain text. Or they could change the content, insert a redirect
by SquareWheel 4y ago
Do you really want your ISP to know which piracy sites you frequent? This is all being sent in plain text. Or they could change the content, insert a redirect, or inject ads without your knowledge. TLS is needed on all websites - not just those with interaction.
- ars 4y agoThey still know which sites you visit even with https.
- kenniskrag 4y agoonly the destination IP. TLS encryption is inside tcp and around the http protocol.
- hombre_fatal 4y agoYou don’t need to copy and paste your reply everywhere it’s relevant on HN. Even us flea brains can carry your remarks in our head and apply them to similar comments.
- geoffeg 4y agoAnd, unless you setup an appropriate DNS server and the default from your ISP, then they also know that you looked up the site's hostname(s).
- pessimizer 4y agoThey don't know the page. In the case of this site it probably doesn't matter, but which page you're looking at is always going to be more interesting and informative than which site you looked at. When the prosecutor is looking through your internet records and they see 50 wikipedia hits in some relevant time period, they're going to be upset that https exists.
- generalizations 4y agohttps won't keep your ISP from knowing you visited the site. And the rest of those? For a text-only blog, they seem kinda trivial.
- robonerd 4y ago> For a text-only blog If somebody MITMs it, they can serve you anything they want.
- enriquto 4y ago> they can serve you anything they want. Great. More books! No really, I don't understand this argument. A static site served by plain http is perfectly appropriate. It's like a poster hanging on the wall for all to see. Of course people can paint over it, but it doesn't really matter.
- robonerd 4y agoThey could serve you javascript that exploits your browser. At the very least, they could replace that bitcoin donation address with their own. That's a tempting target if nothing else.
- SquareWheel 4y agoAnd "they" isn't just your ISP. It's also that free wifi hotspot you connected to, or the hotel service, or your company's network. Even if you trust your ISP (and you probably shouldn't), there are other bad actors to be aware of.
- Aachen 4y agoIf you think you're high value enough to have someone target you specifically by getting on your LAN or gaining access to (or coercing) an upstream ISP to serve you a browser 0-day reachable only by laying in wait for you to visit an HTTP site because there is no other way in, that's not going to be for a free books website.
- cookiengineer 4y agoI hate to break it to you, but why do you think ISPs override the DNS responses with TTL set to 0? TLS itself is only useful if you also rely on DNS over HTTPS/TLS. Well, setting the issues with TLS 1.2 and earlier aside.
- SquareWheel 4y agoThose are problems too, but they aren't exploited nearly as often as MITMing cleartext has been historically. The solution you mention is already becoming widely-supported, as are newer protocols like QUIC that discourage snooping. There's no reason to ignore a good solution just because it's not 100% perfect.
- Tepix 4y ago> why do you think ISPs override the DNS responses with TTL set to 0 mine doesn't.