7 ms·
The Bureau of Meteorology website does not support connections via HTTPS
- ksaho 3y agoWelcome to Australia. This has been an issue for years, and I don't know why.
- defrost 3y agoThe rationale, such as it is, is that BoM serves current and historic weather parameters for various parts of Australia and hasn't seen any need to ensure that be delivered in a secure manner to individual web users. There might be some hypothetical scenario from faking weather data and injecting it to fool the casual user but that seemingly hasn't come up in practice and so they don't fuss about it. On the flip side, for those interested in RAW downloads from MODIS and other sats relevant to the weather, to ground station raw data transfers, to modelled predictions under various assumptions for commercial | military | government use etc ... BOM has secure login and bulk data transfer protocols, and has had those for at least 30+ years (morphing with time).
- samjmck 3y agoI think the more likely scenario for a MITM attack is to insert malicious scripts or links into the web page, not to fake weather data.
- LAC-Tech 3y agoNZ feels behind Australia in most ways. But in this area we're ahead. It's slightly insane to me a country as wealthy as yours still has this sort of thing going on.
- NL807 3y agoI personally know someone working at BOM. His endless ranting about how the place is run is hilarious.
- akdor1154 3y agoI wonder if you could mitm an HSTS header.. short term dick move but might raise enough of a stink for it to be fixed..? I can only dream.
- fowl2 3y agoHSTS headers are only respected on HTTPS connections
- kspacewalk2 3y agoWhat practical difference does it make if I connect to an Australian weather forecast site via HTTP or HTTPS? Is the NZ secret police gonna MITM a rain forecast my way when it's actually gonna be a very sunny day?
- geek_at 3y agoIt's just dangerous because any party on the way between wifi and the server can edit the content See: why are free proxies free https://blog.haschek.at/2013/05/why-free-proxies-are-free-js-infection.html https://blog.haschek.at/2013/05/why-free-proxies-are-free-js...
- defrost 3y agoIn the same way as walking to the bank is dangerous because any party on the way can rob you on the way? I regularly visit: www.bom.gov.au/<mystate>/forecasts/<mytown>.shtml It either shows me the forecast or it doesn't. To date it's always worked - if one day it doesn't I might have to look out of a window.
- Beldin 3y ago> In the same way as walking to the bank is dangerous because any party on the way can rob you on the way? To make this analogy more fitting, you'd also need a big sign around your head "going to do some banking, carrying all necessary credentials, cannot tell legitimate bank from fake bank". Still not a great analogy though.
- 8organicbits 3y agoImagine a major weather event is coming and a warning banner shows on the weather site telling you to stay off the roads. But some carelessly injected ad covers it, or the injected CSS makes it unreadable. You don't see it and suffer a crash. Government communications should not be subjected to arbitrary modification by intermediaries. Ad injection on HTTP is (or at least was, when unencrypted HTTP was popular) common. It also raises the concern that the ad will appear to have government sponsorship, which invites scams and other malvertising. A government agency should seek to communicate information with the public, especially safety information, via an untamperable communication channel.
- springah 3y agoAssuming this has come from Tall Paul Tech’s latest video?
- LAC-Tech 3y agoDJ Tall Paul is a tech youtuber!?! fuck yeah
- cjs_ac 3y agoThe Bureau of Meteorology has form when it comes to computer security incidents[0]. [0] https://www.abc.net.au/news/2018-03-08/bureau-of-meteorology-staff-implicated-in-cryptocurrency-ring/9524208 https://www.abc.net.au/news/2018-03-08/bureau-of-meteorology...
- defrost 3y agoEmployees on the inside using the data cruncher to mine bitcoin isn't a HTTPS issue - given these chancers were caught it appears the BOFH functioned uncorrupted and reported their illicit cycles.
- dottjt 3y agoI remember seeing this yesterday when visiting the site. Wasn't sure if it'd always been like this, or if this was recent.
- exikyut 3y agoProbably your browser trying HTTPS-first
- pophenat 3y agoI find intriguing their explanation about how to use their FTP service and why it’s not possible to access it with a modern browser. http://www.bom.gov.au/catalogue/anon-ftp-hints.shtml http://www.bom.gov.au/catalogue/anon-ftp-hints.shtml
- FpUser 3y agoIt least someone had decided to have common sense.
- ulrischa 3y agoControverse opinion: Why do I need https when looking for the weather forcast. Https is blindly thrown on everything. If the data is public and no login or personal/sensitive data is involved why do I need https?
- mplewis9z 3y agoWhat happens when a site you really do need and have HTTPS on (your bank, say) has a cross-site request forgery vulnerability, and someone plops an exploit script on that non-HTTPS site you visit? With crafty enough hackers, your savings just got wired to a foreign country. The entire internet needs to be HTTPS to protect against stupid security decisions made long ago that we can’t undo now in the name of backwards compatibility.
- JeffSnazzy 3y ago> The entire internet needs to be HTTPS to protect against stupid security decisions made long ago that we can’t undo now in the name of backwards compatibility. We can undo it now, the powers that b just refuse to abandon the altar of backwards compatibility, damn the cost. (Even though the addition of a straightforward document browser with no JS and no dynamic content would seriously improve most of the internet....)
- harrymit907 3y agoYour LE friendly ISP can insert a JS browser exploit and gain access to your device. Is that a valid reason?
- rini17 3y agoMeh, that's all such a theater. LE can ask anyone to insert an "JS exploit", especially into the government meteo service. It will then be nicely safely and securely served to you via HTTPS :) Of course, enabled specially for your IP address so that noone else gets any clue. edit: and everyone is voluntarily mitming via cloudflare anyway..it's all such a farce
- 3y ago
- JonathanBeuys 3y agoHTTPS is still a pain in the ass, even in 2024. If letsencrypt would offer wildcard certificates with their url based authentification as they offer for non-wildcard certificates, it would be ok. But having to tinker with the DNS infrastructure for each project which wants to use domain wide HTTPS is so much hassle.
- lgeorget 3y agoIt depends on your provider though. I can tell from experience that with OVH and their API, it's been easy to set up the automatic renewal via DNS verification. Apparently, the official client has support for the DNS API of 159 providers: https://github.com/acmesh-official/acme.sh/wiki/dnsapi https://github.com/acmesh-official/acme.sh/wiki/dnsapi
- 8organicbits 3y agoWhat's the challenge for you? Does your DNS server not have an API, is it internal politics and process, or something else?
- gia_ferrari 3y agoThe fact that this is on a .gov.au makes it a bit more attractive to targeted MITM attacks, I would think, given a government site's position of authority.
- aaron695 3y ago[dead]
- L_226 3y agoRemember when BoM was pwned [0] by a foreign intelligence service? What about when they wasted $220k [1] on rebranding but ended up scrapping it? [0] - https://www.itnews.com.au/news/asd-reveals-how-the-bureau-of-meteorology-was-hacked-439215 https://www.itnews.com.au/news/asd-reveals-how-the-bureau-of... [1] - https://www.abc.net.au/news/2022-10-19/bureau-meteorology-rebrand-cost-200-thousand/101552620 https://www.abc.net.au/news/2022-10-19/bureau-meteorology-re...
- pwdisswordfishc 3y agoWell, credit where it’s due: given the number of disparaging statements about cryptography made by Australian politicians, it seems they actually practice what they preach.
- einpoklum 3y agoSo? it also doesn't scramble voice calls when you call their offices, I would think.
- slowbdotro 3y agoBack in 2013-15 I was fortunate enough to know some people at BoM, specifically done IT people. Their off hand comment around why BOM didn't have https was due to the amount of overhead and infrastructure changes needed to make that https change. Fast forward to 2018ish they recently created a new API, and a new website. Https://Weather.bom.gov.au with https enabled! (which I now have integrated into a raspberry pi and an eink display for my morning weather). For whatever (archaic) reason the new weather webui is now defunct but the api still exists, uses https, and as far as I know supports their mobile applications. All it would take is for some ISPs here to mitm the traffic with ads / junk and maybe they would change it. The upside to this story is that it is currently a great site to visit for captive portal detection.
- auxesis 3y agoThe reality is much worse. For over a decade the BOM themselves ran ads on their website: https://www.governmentnews.com.au/online-ads-now-permanent-fix-bureau-meteorology/ https://www.governmentnews.com.au/online-ads-now-permanent-f... https://web.archive.org/web/20230605202001/http://www.bom.gov.au/advertising/ https://web.archive.org/web/20230605202001/http://www.bom.go... They appear to have stopped the practice in June 2023: https://web.archive.org/web/20230515000000*/http://www.bom.gov.au/advertising/ https://web.archive.org/web/20230515000000*/http://www.bom.g...
- davidbanham 3y agoI am very interested in this api. How do I get at it? AFAIK the only way to programatically obtain bom data is the awful ftp endpoint.
- slowbdotro 3y ago- https://api.weather.bom.gov.au/v1/ https://api.weather.bom.gov.au/v1/ - https://github.com/tonyallan/weather-au https://github.com/tonyallan/weather-au - https://pypi.org/project/weather-au/ https://pypi.org/project/weather-au/ Enjoy
- la_oveja 3y agoseeing verdana gives me such good memories back. my fav font when i started learning webdev
- matrss 3y agoHonestly, I think every third-party involved in transporting http traffic should do the public a service and replace the transmitted data with some cat images or whatever else. Every unencrypted connection should be messed with so that there cannot be accidental unencrypted transmission of sensitive data, just in case.