4 ms·
shouldiimplementssl.com
by guyzero 1y ago
shouldiimplementssl.com
- branon 1y agoThe explanation I've seen before is that it doesn't really matter for websites that don't _want_ anything from you. No credentials, no login forms, no text entry fields. Maybe there are edge cases associated with this?
- AStonesThrow 1y agoRemember the C-I-A triad of security. I consider the integrity of messages to-and-from the web to be very important. Many of us lived through days when ISPs or some other greedy middleman injected ads into unsecured web pages. They played DNS tricks too. Imagine if you had an app download that could be maliciously modified in-flight. Furthermore, a certificate can guarantee you’re not connected to an imposter. What if the TFA link was redirected to “abevigoda.com”? Catastrophe!
- justin_oaks 1y agoWithout TLS, sometimes still referred to as SSL, a webite's content can be modified by anyone controlling the network path. This includes ISPs and WiFi operators. Sure, your website may have unimportant stuff on it that nobody relies on, but do you want visitors to see ads in your content that you didn't put there?
- baby_souffle 1y ago> The explanation I've seen before is that it doesn't really matter for websites that don't _want_ anything from you. No credentials, no login forms, no text entry fields. Still worth creating a bit of a shield between you and the site to make it just hat much harder for anybody in the middle to inject anything / change anything. Back before Lets Encrypt made it inexcusable to not have https, it was a common-ish prank to MITM all the HTTP traffic you could see and do something harmless like rotate images 180 degrees.
- timewizard 1y agoThat also requires either a shared wifi network or ARP spoofing. It's not something that HTTP itself inherently allows.
- AStonesThrow 1y agoI am not sure what leads you to answer this way, but I assure you that HTTP, like any other unencrypted network traffic, does inherently allow undetected tampering by any middleman. While it's highly unlikely that threat actors would be lurking in trusted networks and devices on such a network path, they definitely don't need to use shared WiFi or ARP spoofing if they have control of a core router or transmission line. That's the very essence of MITM attacks.
- timewizard 1y ago> I am not sure what leads you to answer this way Knowledge of facts and history. What leads people such as yourself to start a response this way? "I'll respond to you but first I'm going to feign ignorance of how you could even say that in a way that adds absolutely nothing to the discussion." I perceive this as exceptionally rude. Am I alone in that? > does inherently allow undetected tampering by any middleman. Yes. And did I describe methods by which you can hijack connections to /become/ the middleman? Perhaps you missed the subtle detail. > That's the very essence of MITM attacks. The popularized attacks you're describing became popular because they were done with the techniques I described in places like Starbucks and other businesses with open Wifi networks. Here it is, literally: https://en.wikipedia.org/wiki/Firesheep https://en.wikipedia.org/wiki/Firesheep
- AStonesThrow 1y agoWell, I interpreted your reply as implying that the only vectors possible were shared WiFi or ARP spoofing. If you merely intended to offer two examples, then it makes more sense. But I am still not sure why your answers are so irrelevant! So, I am still unsure that you are clued in here, because the article you have linked to has nothing at all to do with tampering in-flight TCP streams, only sniffing them. Perhaps you do not understand how these principles differ. This shared WiFi scenario certainly permits eavesdropping on unencrypted channels, and that’s a danger that’s distinct from actual MITM. You claim we’re describing the same thing but we are not. > did I describe methods No, actually you didn’t — you named one vector and one mostly unrelated LAN attack. ARP spoofing may be a stepping stone, but not really central. The attack you describe happens at the application layer, in fact. It doesn’t even need to use TCP. You’re simply stealing someone’s credentials and reusing them in a new browser session. There’s really no way to legitimately describe this as “MITM” — or “tampering” at all. [Your Wikipedia article does not use these terms.] And in a typical Starbucks installation, nobody would realistically attempt to tamper with in-flight TCP streams. Because that attack would involve some elaborate setup, presenting a higher challenge than the Firesheep attack. I am sure you could explain and describe the former, if you understand the underlying principles. No, the classic MITM attacks on http do involve neither WiFi nor ARP, but simply interposing malicious code somewhere else on-path. [Actually it is not necessarily malicious, because NAT gateways work by modifying TCP streams too!] That’s why a newer name is called “on-path attack”. And you seem to have omitted that scenario from your comments.
- kccqzy 1y agoThe website might not be designed to have credentials or login forms, but now you have allowed attackers to place fake login forms on your website. And given the prevalence of password reuse for the general population, attackers can easily harvest real passwords this way. Not to mention injected ads which used to be very common in the late 2000s.
- crote 1y ago> Maybe there are edge cases associated with this? Plenty. There are a lot of information-only websites where you might want to keep your visit to yourself. To give an obvious example: some parts of the United States are trying very hard to make abortion impossible. The state government could mandate that ISPs MitM your traffic, and alert the police when you visit a website giving you information about the legal abortion clinics in a neighboring state. Guess you'll be getting a home visit... The same is going to apply with looking up info on LGBT subjects, civil rights, Tiananmen Square, a religion not explicitly allowed by the state, whether Eurasia has always been at war with Oceania, and so on. Heck, even a seemingly innocent website visit could theoretically come back to haunt you years later. Just some bored scrolling on Wikipedia? Nope, you were planning a crime - why else were you reading pages about chemical warfare during WW I? That neighbor who died due to mixing bleach and ammonia was obviously murdered by you. If it's unencrypted, you should assume it's being logged by someone nefarious. Are you still okay with it?
- briHass 1y agoTo be fair, TLS doesn't stop the authorities from performing dragnet searches. Just supeona Google for search keywords, mobile service providers for geofence data, DNS logs, IP logs from ISPs, etc. If that gives them enough for a warrant, they can get emails, SMS, browser history, account data, and detailed location logs. Not to mention license plate readers, surveillance cam footage and financial transactions. It's honestly surprising that anyone gets away with any significant crimes, given just how much potential evidence is recorded.
- pessimizer 1y agoWithout TLS, people (service providers and intermediaries) can tell what pages I'm reading on your site. They can make the kind of inferences from these that get people convicted at trial. TLS is more important on sites that are just serving information. It's easy to reconstruct your train of thought as you click around. Librarians have fought (and lost) to defend our privacy to read. https://www.ala.org/advocacy/intfreedom/privacyconfidentialityqa https://www.ala.org/advocacy/intfreedom/privacyconfidentiali...
- SAI_Peregrinus 1y agoIn addition to what everyone else has said, having everything be encrypted means encryption isn't "special", there's no metadata that indicates that the communication contains secret data due to encryption. If people don't encrypt non-sensitive traffic, then sensitive traffic stands out. So there's a sort of civic duty element to enabling TLS (or using encrypted messaging, etc.).
- immibis 1y agoI used to think that, but at this point the Internet is sufficiently hostile that it's everyone's responsibility to encrypt everything all the time to reduce the utility to bad actors to zero. It's a little bit like using Tor for some of your ordinary browsing (which I do) so that spy agencies can't infer everyone using Tor is doing something wrong.
- yjftsjthsd-h 1y agohttps://doesmysiteneedhttps.com/ https://doesmysiteneedhttps.com/ , actually
- guyzero 1y agoThank you!