18 ms·
Chesterton's Fence - why did everyone start encyrpting their websites? His critiques of why LE is flawed security wise are spot on and I suspect something like
by eduction 1y ago
Chesterton's Fence - why did everyone start encyrpting their websites?
His critiques of why LE is flawed security wise are spot on and I suspect something like SSH keys as he suggests would be pretty much as good.
But there's a reason we're encrypting everything, and the time when we started encrypting offers a clue as to why. Mass surveillance threat actors are not going to go to the trouble and visibility of MITMing every cert connection, but they will (and in the case of NSA did) happily go to the trouble of hoovering up network traffic en masse and watching how people surf. HTTPS provides some protection there because it at least hides the paths to the specific pages you are reading as you surf online, including things like search engine query terms.
The idea that $3.6m is a lot of money to encrypt a huge chunk of web traffic, or that Google is eagerly guarding the money it makes (?) off web certs, which must be a tiny fraction of its actual income, is a clue that this is maybe not a greedy conspiracy.
- SoftTalker 1y ago> why did everyone start encyrpting their websites Because Google forced us to, by throwing up scary warnings if we didn't do it. Google doesn't care about $3.6mm. They do care about the additional control they have by this scheme. > [HTTPS] at least hides the paths to the specific pages you are reading as you surf online, including things like search engine query terms. This assumes there isn't a secret firehose feed from Google to the NSA, which I don't think is a safe assumption.
- philistine 1y agoWhat control does it give them? I'm far more amenable to the idea that Google didn't want ISPs to start injecting ads on websites. If that is control for Google in your view, then my interests aligned with Google for once in a blue moon.
- grepps09 1y agoVery much agree on the last point. Controlling the de facto CA for all non-corporate web sites still gives Google a lot of control over who gets to be visible on the Internet, and that’s where the value in LE is. The direct income from SSL certs are completely insignificant.