5 ms·
There are dozens of us I guess that care about this kind of thing. I have never really understood the obsession with https for static content that I don't care
by kevstev 1y ago
There are dozens of us I guess that care about this kind of thing. I have never really understood the obsession with https for static content that I don't care if anyone can see I am reading like a blog post. HTTPS should be for things that matter, everything else can, and think should use HTTP when it is not necessary.
Depending on yet another third party to provide what is IMHO a luxury should not be required, and I have been continually confused as to why it is being forced down everyone's throat.
- derf_ 1y ago>There are dozens of us I guess... Shine on you crazy diamond, and all that, but... > I have been continually confused as to why it is being forced down everyone's throat. Have you never sat on public wifi and tried to open an http site? These days it is highly likely to be MITM'd by the wifi provider to inject ads (or worse). Even residential ISPs that one pays for cannot be trusted not to inject content, if given the opportunity, because they noticed that they are monopolies and most users cannot do anything about it. You don't get to choose the threat model of those who visit your site.
- sam_lowry_ 1y agoHave you ever opened your work laptop? It is likely MITM'd so that your employer can see everything you read and post on the internet and HTTPS won't help you.
- DaSHacka 1y agoSo? I own more devices than a work laptop. I would like to have privacy and security on those.
- varjag 1y agoHave you never sat on public wifi and tried to open an http site? These days it is highly likely to be MITM'd by the wifi provider to inject ads (or worse). I honestly don't remember a single case where that happened to me. Internet user since 1997.
- homebrewer 1y agoWhich blog post? If it's anything remotely political or controversial, people have disappeared for that. You can always spot someone on HN who has never stepped outside their cushy life in a liberal democracy. The difference in mentality — between how "you" and "we" see the world — is crazy.
- dwaite 1y agoThe issue is that static content only sites do not exist - unless browsers change their stance to disabling long-relied-upon features like Javascript and embedded frames for content served over plain HTTP. They've taken that strategy with newer enhancements (for instance, you can't use passkeys over non-secured channels), but the bar for widespread breakage of existing deployments is pretty high - even if changes like this make it harder to navigate to those existing deployments.
- layer8 1y ago> The issue is that static content only sites do not exist You’re exaggerating a bit. I have a static website that hasn’t changed in over 15 years. Okay, not completely static, as one page has a (static) HTML form that creates some file templates as a utility, but everything is working like it did in 2010. Except that I added TLS support at some point so that people don’t get scary warnings.
- cle 1y agoThere are good arguments for it, but it's also not a coincidence that they happen to align with Google's business objectives. Ex it's hard to issue a TLS cert without notifying Google of it.
- tracker1 1y agoI don't get your logic/reasoning here... could you explain?
- 01HNNWZ0MV43FF 1y agoThere are public logs of every TLS cert issued by the major providers. This benefits Google. Kinda like how Wikipedia benefits Google. Or public roads benefit Uber. Or clean water benefits restaurants
- tracker1 1y agoGoogle also knows about every domain name that gets renewed or registered... How does knowing a website has tls help in any meaningful way that would detract from society as a whole?
- dspillett 1y agoThe certificate transparency log lets everyone know which domains are active as the certificates are getting renewed, likely more often than the domain itself, and also which sub-domains are active if those are not secured using a wild-card certificate. Not just Google: AI bots could use the information to look for juicy new data to scrape and ingest. Probably not a significant thing, the information can be derived in other ways too if someone wants to track these things, but it is a thing.
- tracker1 1y agoThis doesn't feel like much of an argument in favor of not using https though.
- IgorPartola 1y agoIt’s static while you control it. Soon as I MIIT your content it will look to your users like you updated your site with a crypto miner and a credit card form. You can publish your site with a self-signed key if you’d like and only depend on your ISP/web host provider, DNS provider, domain registrar, and the makers of your host OS and web server and a few dozen other things.
- GaryBluto 1y ago> MIIT Man in in the?
- IgorPartola 1y agoTypos happen :)
- afavour 1y agoMan In Icy Tundra
- kaoD 1y agoJust because you don't care doesn't mean nobody cares. I don't want anyone snooping on what I browse regardless of how "safe" someone thinks it is. My navigation habits are boring but they are mine, not anyone else's to see. A server has no way to know whether the user cares or not, so they are not in a position to choose the user's privacy preferences. Also: a page might be fully static, but I wouldn't want $GOVERNMENT or $ISP or $UNIVERSITY_IT_DEPARTMENT to inject propaganda, censor... Just because it's safe for you doesn't mean it's safe for everyone.
- msla 1y agoAnd so we got The Usual Conversation: "I want my communications to be as secure as practical." "Ah, but they're not totally secure! Which means they're totally insecure! Which means you might as well write your bank statements on postcards and mail them to the town gossip!" It amazes me how anti-HTTPS some people can be.
- sam_lowry_ 1y agoSo... do you refuse to use the laptop supplied by your employer? It does MITM between you and the HTTPS websites you browse.
- AndrewStephens 1y agoThis is still not that common but I used to work on a commercial web proxy that did exactly this. The only way it works is if the company pushes out a new root certificate via group policy (or something similar) so that the proxy can re-encrypt the data. Users can tell that this is being done by examining the certificate. But this is mostly a waste of time, these days companies just install agents on each laptop to monitor activity. If you do not own the machine/network you are using then don’t visit sites hat you don’t want them to see.
- dspillett 1y ago> So... do you refuse to use the laptop supplied by your employer? For things other than work for my employer? Yes. And work stuff doesn't touch my personal equipment, with the exception that I can connect to the company VPN from my personal laptop to remote to a work machine if I need to do DayJob work remote in an emergency when I don't have the company laptop with me. > It does MITM between you and the HTTPS websites you browse. My employer doesn't. Many don't. Of course many do, but that is them controlling what happens on their equipment and they are usually up front about it. This is quite different to an ISP, shady WiFi operator, or other adversarial network node, inspecting and perhaps modifying what I look at behind my back.
- kstrauser 1y ago> HTTPS should be for things that matter If that were the universal state, then it would be easy to tell when someone was visiting a site that mattered, and you could probably infer a lot about it by looking at the cleartext of the non-HTTPS side they were viewing right before they went to it.
- ndriscoll 1y agoYou can already see what site someone visits with HTTPS. It's in the Client Hello, and is important for things like L4 load balancing (e.g. HAProxy can look at the host to choose what backend to forward the TCP packets for that connection to without terminating TLS). It's also important for network operators (e.g. you at home) to be able to filter unwanted traffic (e.g. Google's).
- kaoD 1y agohttps://blog.cloudflare.com/announcing-encrypted-client-hello/ https://blog.cloudflare.com/announcing-encrypted-client-hell...
- ndriscoll 1y agoYes that's why I listed a couple reasons why adopting ECH everywhere is not straightforwardly all good. The network operator one in particular is I think quite important. It happens that the same company with the largest pushes for "privacy" (Google) has also been constantly making it more difficult to make traffic transparent to the actual device owner (e.g. making it so you can't just drop a CA onto your phone and have all apps trust it). Things like DoH, ECH, and ubiquitous TLS (with half the web making an opaque connection to the same Cloudflare IPs) then become weaponized against device owners. AFAIK it's still not that widely adopted or can be easily blocked/disabled on a network though.
- kaoD 1y agoThat sounds like an Android issue, not a TLS issue. If I need to break TLS I can add my own CA. Not having TLS is not the solution. Google will find other ways to take control from you.
- bigstrat2003 1y agoAgreed. I think that the push to make everything HTTPS is completely unnecessary, and in fact counterproductive to security. By throwing scary warnings in front of users when there is no actual security threat, we teach users that the scary warnings don't matter and they just should click past them. Warning when a site doesn't use TLS is a clear cut case of crying wolf.
- ndsipa_pomu 1y agoWhat would the alternative be? Not warn users when they're about to login to a website that's pretending to be their bank?
- DaSHacka 1y agoClearly the alternative is to return to HTTP, as these users are suggesting. Surprised they're still posting, with their employers being shut down at the moment and all.
- dns_snek 1y ago> Warning when a site doesn't use TLS is a clear cut case of crying wolf. No, it's a warning sign that you may be an active victim of an HTTPS downgrade attack where an attacker is blocking HTTPS communication and presenting you with an HTTP version of the website that you intended to visit, capturing and modifying any information you transmit and receive. > By throwing scary warnings in front of users when there is no actual security threat Most of these situations may be innocent but the problem is that they look identical to "actual security threats" so you don't have a choice. If there was a way to distinguish between them we/they would be doing it already.
- ozim 1y agoYou just clearly don’t understand it is important that no one injects anything into your code while I am browsing it. With http it is trivial. So you say you don’t care if my ISP injects whole bunch of ads and I don’t even see your content but only the ads and I blame you for duping me into watching them. Nowadays VPN providers are popular what if someone buys VPN service from the shitty ones and gets treated like I wrote above and it is your reputation of your blog devastated.
- sam_lowry_ 1y agoMy ISP does not and if yours does, vote with your money or lobby your government to make this illegal. And while at it, lobby to make corporate MiTM tools illegal as well. Because if you are bothered about my little blog, you should be bothered that your employer can inspect all your HTTPS traffic.
- graynk 1y agoOr you could do a much simpler thing and support HTTPS and not expect users to change ISPs (which is not always possible, e.g. in rural areas) or change laws (which is even less realistic) to browse your (or any other) blog. Injecting ads has nothing to do with corporate MITM, it's unquestionably bad, but unrelated here. More to the point: serving your blog with HTTPS via Let's Encrypt does not in any way forbid you from also serving it with HTTP without "depending on third parties to publish content online". It would take away from the drama of the statement though, I suppose.
- ozim 1y agoTo add to that rouge ISP employees don’t care if it is illegal.
- dns_snek 1y agoIt's not just your ISP, it's anyone on the entire network path, and on most networks with average security that includes any device on your local network.