4 ms·
I don't get what you're asking. Why is HTTP/S important?? I don't know how to answer that for you. Security is important regardless of where it is at. Defense i
by PenguinCoder 4y ago
I don't get what you're asking. Why is HTTP/S important?? I don't know how to answer that for you. Security is important regardless of where it is at. Defense in depth, at multiple layers. I don't fear MITM on a local only HTTPS server, I might not trust other devices/traffic on my network that scoop up _everything_ it can, and being in plaintext, would expose more than I want. I trust my services and devices. I don't trust everything on the network especially devices that are not mine, or that I have no control over (set top boxes, Roku TVs, Sec Cameras/NVRs, etc). Of course I have other controls and protections in place, but I trust and WANT LOCAL HTTPS on my services in addition to those.
- diarrhea 4y ago> I don't fear MITM on a local only HTTPS server > I trust my services and devices That is exactly the point. You trust your local, possibly dumb aka unmanaged switch. It's a little piece of silicone with no funny business going on. Now if you plug a trusted device A as well as an untrusted device B in, the untrusted device won't see any traffic meant for device A: https://wiki.wireshark.org/CaptureSetup/Ethernet#switched-ethernet https://wiki.wireshark.org/CaptureSetup/Ethernet#switched-et... Point being: as long as you trust all network devices from a trusted machine to another, on a switched Ethernet network, no other device will see any of that traffic at all, on a fundamental, low OSI level. It's not even about HTTP/S at that point yet. All this is untrue for WiFi, where you will want HTTPS indeed. I'm not advocating against HTTPS at all. I use it as much as possible. But it might actually not be necessary, locally under the right circumstances.