3 ms·
Https is a wrapper around http. The result is that any service that needs any http information can decrypt all https traffic. So on the web, passwords, apikeys,
by AtNightWeCode 4y ago
Https is a wrapper around http. The result is that any service that needs any http information can decrypt all https traffic. So on the web, passwords, apikeys, personal information and so is in general decrypted by a third party, Fastly, Akamai, Cloudflare and so on.
- barsonme 4y agoThat is entirely untrue. HTTPS is just HTTP encrypted with TLS. The only parties that can decrypt the traffic are the people with the session keys: you and the website you’re visiting.
- AtNightWeCode 4y agoYou are plain wrong.
- barsonme 4y agoHow so?
- AtNightWeCode 4y agoCause requests are often sent through any of the large third-party layer 7 reverse proxy networks that sits between the user and the origin host.
- barsonme 4y agoAll they see is ciphertext unless they’re terminating TLS and forwarding your traffic on to the target website.
- AtNightWeCode 4y agoThey are terminating TLS.
- barsonme 4y agoNot sure how this is a problem with HTTPS, then. It’s like complaining that AES encryption is broken because you have away your keys to a bunch of people.
- AtNightWeCode 4y agoIt is a problem with HTTPS as it removes capabilities of HTTP without offering any other solution except terminating TLS.
- barsonme 4y agoWhat you’ve said so far has been generally confused and incorrect. I would suggest doing more research about HTTPS.
- AtNightWeCode 4y agoSays the guy who did not even know that all these reverse proxies like Cloudflare does TLS termination on the edge.
- parasubvert 4y agoYou’re glossing over that these third parties C are contracted trusted parties of entity B and thus for B’s purposes are considered part of B. HTTPS and transport security isn’t a broken idea. Standardized content security has been tried in many contexts and has typically been even less secure unless it’s for long lived opaque media, like S/MIME for emails. Structured data like XML security has been abysmal.