35 ms·
The irony, starts a cryptography association and doesn't even use SSL.
by nullbyte808 4y ago
The irony, starts a cryptography association and doesn't even use SSL.
- benreesman 4y agoPossible (half-serious) counter-point: people who understand cryptography know when it is and isn't necessary and don't need to default it on for everything like the rest of us mortals?
- xurukefi 4y agoSerious counter-counter-point for anybody interested: HTTPS protects people from ISP-based MITM attacks. This by itself is more than enough reason to always use HTTPS if your website can be accessed by other people, even if it is just a small little innocent static blob of HTML.
- EGreg 4y agoCan’t the ISP still know what site you are visiting?
- mholt 4y agoNot necessarily. That's a simple question with a complex answer. There's a lot of "ifs" and maybes and it depends a lot on how the site is set up internally.
- Graziano_M 4y agoThat’s not really the point. Say the MITM just replaces the phone number with one of their own so that a potential client calls the wrong number and pays the wrong person.
- ramblerman 4y agodoesn't man in the middle only apply if there were forms or anything requiring user input. I.e. a portion of the website is real, but the user interaction is attacked with MITM. If the risk is that an ISP would spoof the entire website at AI, then that can be done regardless of HTTPS.
- xurukefi 4y ago> If the risk is that an ISP would spoof the entire website at AI, then that can be done regardless of HTTPS. No, an ISP cannot spoof a valid certificate for a website
- otabdeveloper4 4y ago> HTTPS protects people from ISP-based MITM attacks On the infinite list things to worry about, "ISP-based MITM attacks" ranks somewhere around "getting bitten by a shark while fighting a velociraptor" and "accidentally getting abducted by a UFO". Please, please, let's start solving real problems. P.S. I know about dishonest ISP's that try to inject ads into pages. Switch to a better ISP, problem solved.
- xurukefi 4y ago> Switch to a better ISP, problem solved. There are a lot of people in this world who can choose between exactly one ISP.
- otabdeveloper4 4y agoThere are a lot of people who can choose between exactly one supermarket. Should you equip everyone in the world with an e-coli tester? You know, it's super-easy for a supermarket employee to infect your food with e-coli! Some problems don't need a technical solution, okay?
- paledot 4y agoIn 2022, the strongest possible argument against using HTTPS is "it's not strictly necessary". That's it. It's not expensive, it's not hard, it's not slow. The worst case is you've done something unnecessary for most people (arguably). Yeah, if "e-coli testers" were free, easy to distribute, and consumed no resources, including them with every supermarket purchase would be a great idea.
- Rudism 4y agoAlso if it has been proven that, given a chance, many supermarkets have and still actively do inject e-coli into their foods because they are able to profit off of it somehow, then the "e-coli testers" would be an even better idea.
- deleted 4y ago
- mholt 4y agoThose who know, know, that selectively using encryption creates metadata that paints targets on more sensitive communications
- benreesman 4y agoThis is the sort of thing that lay people like me imagine that serious infosec pros would pay attention to. But to be perfectly honest: between the uncle with TS at a defense contractor, the ex-girlfriend Political Science valedictorian with an Arabic minor who “taught English” in Waziristan, and the pre-IPO Facebook job, I just sort of assume that if the Equation Group wants to know if I watch Internet porn, “I will do nothing, because I can do nothing”.
- benreesman 4y agoI was just kidding around folks: obviously TLS is the right default. Incidentally you can bet your ass that someone at YC has a model of their amortized differential deal flow per page view and that they work harder at keeping it up-to-date than the RustHN discord channel where they call in the Team. So troll-ass threads like this are pure free-ride.
- notfed 4y agoSeemingly none of these TLD-only domains have valid certs. Perhaps no certificate authority will sign this format?