6 ms·
Basically they are destroying the simplicity of the internet in order to push their own agenda. I'd get annoyed about it, but it's not going to be long before i
by jbb555 12y ago
Basically they are destroying the simplicity of the internet in order to push their own agenda. I'd get annoyed about it, but it's not going to be long before it all collapses under it's own weight and something new and lightweight turns up to take over from what http used to be good for.
- fpgeek 12y agoDid you even look at the kinds of attacks that motivate these restrictions before concluding that there was a nefarious agenda at work? I took a look at a Fullscreen API attack ( http://feross.org/html5-fullscreen-api-attack/ http://feross.org/html5-fullscreen-api-attack/ ) and found it pretty creepy even though I knew exactly what to expect and what to look for. Tighter controls over that sort of thing seem like a great idea to me.
- ldng 12y agoMaybe I'm dense but I don't see how requiring HTTPS would solve phishing attacks. To me it falls in the social engineering realm, people clicking link in their mail thay really should not. Having an extra 's' in the URL will not change that. Am I missing the point ?
- TazeTSchnitzel 12y ago1) You need to have been approved by a CA to get a TLS certificate 2) If HTTPS is required, MITMing can't be used to take advantage of permissions you've granted to existing sites
- ldng 12y ago1) Expensive for no good reason for 80% of sites out there 2) We agree it is useful in some case. That what makes it hard to go against, because it seems a reasonable objective. The problem is where do you put the limit. I don't "fullscreen" my bank account. To me, forbidding fullscreen on HTTP is quite over the top but fits Google agenda of HTTPSing All The Things.
- icebraining 12y agoI don't "fullscreen" my bank account. They don't want to prevent you from fullscreening on HTTP. They want to prevent websites from fullscreening your browser on their own accord using the Fullscreen API, which is quite different. HTTPS might be expensive for 80% of the sites, but 80% of sites don't use the Fullscreen API anyway. Frankly, I think people here should read and understand more carefully what the Chrome team is actually saying before accusing them of nefarious intent (it's fine to accuse them after carefully understanding, of course).
- ldng 12y agoGoogle elsewhere, another time, kind of said that they'll be pushing for HTTPS "all-the-thing". It is their agenda. An agenda I do not juge nefarious, just one I disagree with. That said, I've gone back reread the mail and you're right, I probably jumped the gun a bit here. I did understood "migrate these features to secure-only" as disabling those features on non-HTTPS at mid/long term. I think HTTPS "all-the-thing" trend is not necessarily a good thing. It is not _always_ needed, it can had complexity, it has a cost a it leads to an over simplification of security in general. It is a trend that annoys me a bit and I sometimes overreact about it. Note that I distinguish HTTPS "all-the-thing" from HTTPS "when and where it is needed" for security concerns.
- fpgeek 12y agoIf I click on https://foobarbaz.com https://foobarbaz.com and get phishsed then I know that either foobarbaz.com had something to do with it or certificate verification has been compromised. If I click on http://foobarbaz.com http://foobarbaz.com anyone who can successfully mess with that HTTP connection (a much wider universe of attackers that I have less visibility into, especially if I frequently use different networks [home, work, mobile, etc.]) could have been responsible.
- ldng 12y agoThe thing is most phising attack don't even bother going that far, some people will click on https://foobazbar.com https://foobazbar.com for a "rightly" crafted mail. HTTPS does not prevent anything here.
- organsnyder 12y agoHere's the scenario they're trying to prevent: 1. Bob often views videos on YouTube, so he grants youtube.com permanent access to the fullscreen API. 2. Eve runs an open wifi AP near a coffee shop. The AP includes a proxy server that redirects youtube.com requests to Eve's own server. 3. Bob connects to Eve's AP. When he goes to youtube.com, he instead gets a response from Eve's server, which is designed to imitate a full desktop environment. Since Bob has already given youtube.com access to the fullscreen API, the browser grants Eve's site fullscreen rights without notifying Bob.
- ldng 12y agoOk. Here I can see the problem. That said, does this happens really that much ? Shouldn't we educate on open wifi instead ? My point is HTTPS has a cost and is a barrier of entry, the trade off isn't always worth it, IMHO.
- icebraining 12y agoOpen Wifi is not necessarily the problem. An AP with a shared password (99% of them) is also vulnerable, if the attacker also has a password. It's not reasonable to expect people to never use YouTube on public WiFi hotspots. And the cost of HTTPS is pretty low nowadays. Cloudflare even offers it on their free plan, and it doesn't require you to set it up on your own server.
- ldng 12y agoDo you really need to secure Youtube viewing on a public WiFi hotspots ? Unless you want to sell DRM movies, I don't see the need for HTTPS here. Unless you want privacy on a public network. But we're not talking about security anymore. So you're suggesting trading a potential MitM but an official Cloudflare MitM ? :) It is not only about a money cost, it is also about a complexity cost and false sense of security. HTTPS is not the be-all and the end-all of security. Just a step to security, if/when you need it. I'm not arguing HTTPS is not needed. I'm the first to push for when needed. But it is not needed for watching cat videos, sorry.
- dchest 12y agoGo here and click on the link to BoA website in the side bar: http://en.wikipedia.org/wiki/Bank_of_America http://en.wikipedia.org/wiki/Bank_of_America Anyone in the middle between you and Wikipedia servers can apply the phishing attack. If you go here: https://en.wikipedia.org/wiki/Bank_of_America https://en.wikipedia.org/wiki/Bank_of_America Only Wikipedia editors/admins can perform the attack.
- ldng 12y agoThat is why I don't click on links to my bank but rather type the URL ;-) There is so much you can do to help with phising. HTTPS everywhere is not IMHO a solution. It could even lead to a false sense of security. It's more, HTTPS is the tip of the iceberg. Your bank should send a SMS to confirm any potentially litigious action (mine does). Security is a trade off. Some sites that really need high levels of security (and they are not that many) could say, look, I have HTTPS, you're safe. Errr ... no ... they are some much more you could/should do.
- philh 12y agoBut that attack works just as well if feross.org uses SSL, doesn't it? I'm not sure what MITM+fullscreen gets an attacker that they don't get from either by itself. Which isn't to say there's no reason to only allow fullscreen over SSL, but I can't offhand think of one.
- userbinator 12y agoMemories of receiving tons of full-screen popup and popunder ads (and without any close buttons, address bars, or any other browser controls... thankfully I knew what Alt+F4 did at the time!) may have biased me a bit... but I think the fullscreen API is a bad idea in general - the browser should not allow scripts to do things that modify the UI outside of the content area of the page. If the user wants to resize the content area, he/she should do that through the facilities the OS window manager already provides. Besides, a similar attack could be carried out even without the fullscreen API - just replace the page contents when the link is clicked, and the same people who don't notice the changes in UI will probably not notice the address bar either (it also doesn't help that browsers are attempting to deemphasise/hide the URL...) If they wanted "tighter controls", they should just remove the fullscreen API. I guess a lot of web developers won't like it, but the user has always had the ability to fullscreen the browser if he/she wanted to.
- icebraining 12y agoI don't understand your criticism. They are requiring HTTPS to use complex/advanced features. You're still free to serve your handwritten HTML 4.0 over unencrypted HTTP 1.1. What simplicity is being destroyed here? If anything, they're making it more costly to make complex websites.
- cotillion 12y agoI guess he's one of those who can decode both transfer-encoding and content-encoding in real time while watching tcpdump output. For the rest of us who need tools to watch HTTP 1.1 this changes nothing.
- anon4 12y agoOne thing I'll definitely miss is being able to look at traffic with wireshark. I've used it to great effect when I had to debug a failing service and wanted to see exactly what the browser was sending that was tripping it.
- JustGotHere 12y agoIs it not posible to grab the binary stream and decode it, just like the browser would, on the fly with wireshark?
- CHY872 12y agoYou'd have to find the key used, which would be hidden inside of the browser's memory (and possibly hard to get out). Wireshark will do that for you, but it's not ideal. A more usable way is: Set up a proxy on your system that decrypts and re-encrypts all SSL traffic - effectively acting as the browser. It re-encrypts with its own (auto generated) key, but you've put it's signing key in your truststore so your browser doesn't care. In the middle, you can see what's going on using Wireshark. It's what most corporate firewalls do, as well as that Lenovo software etc.
- CHY872 12y agoThere are other tools that work for this, though. For example, Fiddler.
- colinramsay 12y ago"Agenda"? What, the nefarious agenda of making things more secure for everyone?
- userbinator 12y agoWhile in this case it could be going a little too far since I see how some of these APIs could be used to gather quite sensitive information, it might be a sort of knee-jerk reaction against the trend of "it's for your security" restrictionism that is becoming very common today; and it's a reaction that I think is long overdue... "more secure for everyone" is the same reason often used to justify mass surveillance.
- idibidiart 12y agoNot just that.... did you see the recent report about suspicious root CAs installed on Macbooks? Have you heard about the DigiNotar case where Iranian agents infiltrated the CA? Do you know that private companies MITM HTTPS connections to spy on their employees gmail and facebook activities under data loss prevention policy? HTTPS is clear text to nation states because security is ultimately a physical business. All solutions I've heard of for the "bad CA" problem are themselves insecure. So the only thing the forced moed to https is doing is breaking the internet, adding overhead and creating a two tiered security model: nation states can spy but petty criminals can't. It's fake security in the end, and yes it does come with other concerning implications. But you can't stop it. Tim Berners Lee couldn't. He tried. He continues to try. No one will listen.