4 ms·
This take is really not crediting the different threat models motivating SSH versus HTTPS. In both cases the network is considered untrusted, but beyond this th
by ahefner 4y ago
This take is really not crediting the different threat models motivating SSH versus HTTPS. In both cases the network is considered untrusted, but beyond this the analogy largely fails - almost every application of telnet risks leaking authentication credentials to an eavesdropper (in addition to allowing them to subsequently surveil your session), whereas the classical HTTP use case is to retrieve information anonymously. I cheered the widespread move toward HTTPS as a response to outrageous behavior by certain ISPs and their modifying/injecting content into sessions, which arguably should be criminalized, yet if the forces of abusive service providers and unaccountable state security agencies is becoming so omnipresent that we can only retreat beyond a veil of encryption, we are living in very dark times.
I'd be more optimistic if not for the (cynical?) fear that those most in need of encryption will be the first to be denied it by the force of the state, a day only accelerated by its increasing ubiquity. Your government can force you to install a state-sanctioned CA cert, almost entirely undermining TLS from that perspective, which Google can/will do nothing to resist, and their parallel desire to deprecate plaintext HTTP is entirely orthogonal to this.