4 ms·
I envy you, citizens of the free world :) You (mostly) can use HTTPS, avoid government surveillance, and use new shiny Mozilla features (for whatever they are g
by jsn 11y ago
I envy you, citizens of the free world :) You (mostly) can use HTTPS, avoid government surveillance, and use new shiny Mozilla features (for whatever they are going to be).
It's not the same in e.g. Russia (and I'm sure it's not just Russia). In Russia, the Web is now officially being censored by the state. They have a national register of prohibited resources -- basically, a huge list of URLs. Every ISP must block all access to those URLs, or else.
So if a page (perhaps, a comment page?) on your site enters the register, and it is served over unencrypted HTTP, ISPs can use DPI to block the access to just that specific page -- which sucks, but at least your site is still accessible. If, however, you use HTTPS -- then ISPs have no other choice but to block all traffic to your site entirely. Given that choice, many webmasters (myself included) will have to choose plain HTTP.
- peteretep 11y ago> then ISPs have no other choice but to block all traffic > to your site entirely. Given that choice, many > webmasters (myself included) will have to choose plain > HTTP At some point, blocking CDNs at IP level becomes too much of an economic burden on a country to be feasible. We've seen an unwillingness by the Chinese to block access to GitHub; presumably this means Fastly (their CDN provider) is safe for a while.
- jsn 11y agoDid you know that Russians had github blocked for several days? Anyway, you're talking about counter-censorship warfare. Yes, some of those measures will be somewhat effective sometimes, but the costs (not necessarily even monetary) are actually quite substantial, and it's definitely not for everyone.
- teraflop 11y agoIf you want your ISP to be able to intercept your traffic and see which URLs you're accessing, you could always let them install their own CA certificate on your machine. Then they could proxy and filter to their heart's desire, even over HTTPS. (only half-joking...)
- igorm 11y agoLooks like citizens of free world experienced PRISM program http://en.wikipedia.org/wiki/PRISM_(surveillance_program) http://en.wikipedia.org/wiki/PRISM_(surveillance_program) So, apparently does not matter how many web-services would be secured by HTTPS, there's no problem to spy, and there's always the way to make owners (even if it's Google) let governments use their data - does not matter whether it's encrypted or not. Moreover, in Russia this list is available for everyone, but PRISM has been revealed to public only by Snowden.