3 ms·
I'm not sure I follow your argument. You do realize that you are talking about two different kinds of attack channels right? Cleartext-based attacks and snoop
by chavesn 12y ago
I'm not sure I follow your argument. You do realize that you are talking about two different kinds of attack channels right?
Cleartext-based attacks and snooping (middleman, network peer) are simply far easier and far more likely.
You know those happen all the time, right? Literally all the time for certain users in certain places. A cleartext exploit is source-based (or route-based) and the server owner can't ever do anything to fix it besides forcing encryption (or shutting down completely to that source).
In contrast, a server compromise is destination-based and will theoretically only exist for the time that it is not known to the server provider.
- userbinator 12y agoOn the other hand, cleartext-based attacks are also more easy to detect since the traffic is plainly visible. The maliciousness doesn't always have to be outside, despite all the focus on surveillance recently; and when it isn't, a "secure" connection makes it even harder to detect until it's too late. Here's a recent demonstration of this principle - "smart TVs" phoning home via an unencrypted connection: http://arstechnica.com/security/2013/11/smart-tv-from-lg-phones-home-with-users-viewing-habits-usb-file-names/ http://arstechnica.com/security/2013/11/smart-tv-from-lg-pho... If that was over HTTPS, would such data collection have been as obvious or even discoverable? It would be completely indistinguishable from any other "phoning home" - e.g. to legitimately check for software updates. The same encryption technologies that purport to protect us from mass surveillance... can be used to do it even more stealthily, and this is the main concern I have with making encryption ubiquitous.
- chavesn 12y agoInteresting, though I don't know how this is really relevant to the debate about whether it's appropriate to tell a user that HTTP is insecure but HTTPS is secure (the comment I was replying to questioned that exact point). That's because the technology clearly exists to hide the type of phoning-home you are talking about. Any move toward more HTTPS for end users doesn't seem to increase that risk to me.
- 1stop 12y agoYou know you sound like a condescending prick, right? Client compromises happen a lot (I mentioned them too). My point was "security of connection" != "security of service". But when user sees green padlock, they assume the latter. This feels as though its caused by the conflation of Certificates (Identity), Encryption (SSL), and Privacy into one big ball we call: Valid HTTPS (aka. Green Padlock with your company name in the URL bar). Do these all have to be the same thing? Are Certificate Authorities really the answer? Given Chrome (the browser) is run by a company that scrapes the internet every 3 seconds... can that not be used to verify content/server/etc?