3 ms·
Https is among the most broken ideas in the history of CS. I remember the first time I really learned about it and I went like it can't be this stupid. Most In
by AtNightWeCode 4y ago
Https is among the most broken ideas in the history of CS. I remember the first time I really learned about it and I went like it can't be this stupid.
Most Internet traffic today between A and B is decrypted by C because of this.
- barsonme 4y agoWhat are you talking about?
- AtNightWeCode 4y agoHttps is a wrapper around http. The result is that any service that needs any http information can decrypt all https traffic. So on the web, passwords, apikeys, personal information and so is in general decrypted by a third party, Fastly, Akamai, Cloudflare and so on.
- barsonme 4y agoThat is entirely untrue. HTTPS is just HTTP encrypted with TLS. The only parties that can decrypt the traffic are the people with the session keys: you and the website you’re visiting.
- AtNightWeCode 4y agoYou are plain wrong.
- barsonme 4y agoHow so?
- AtNightWeCode 4y agoCause requests are often sent through any of the large third-party layer 7 reverse proxy networks that sits between the user and the origin host.
- barsonme 4y agoAll they see is ciphertext unless they’re terminating TLS and forwarding your traffic on to the target website.
- AtNightWeCode 4y agoThey are terminating TLS.
- barsonme 4y agoNot sure how this is a problem with HTTPS, then. It’s like complaining that AES encryption is broken because you have away your keys to a bunch of people.
- AtNightWeCode 4y agoIt is a problem with HTTPS as it removes capabilities of HTTP without offering any other solution except terminating TLS.
- barsonme 4y agoWhat you’ve said so far has been generally confused and incorrect. I would suggest doing more research about HTTPS.
- AtNightWeCode 4y agoSays the guy who did not even know that all these reverse proxies like Cloudflare does TLS termination on the edge.