Hacked in a public space? Thanks, HTTPS
theregister.co.uk
theregister.co.uk
> strict-transport-security:max-age=10886400; includeSubdomains
This sensational article fails to mention that.
To protect your website visitors, enable the HSTS header on your web server. Basically just use SSL Labs[2] and fix everything until you have an A+ rating.
[1] https://en.wikipedia.org/wiki/HTTP_Strict_Transport_Security
[2] https://www.ssllabs.com/ssltest/analyze.html?d=wakatime.com
I did this a while back for several of my domains and it was easy and fast. One new problem I have is that after getting on the list and moving the static HTML sites over to CloudFront's free HTTPS offering, I see Chrome 50+ will require that you keep sending the 'preload' header directive, which is impossible to do with CloudFront. Bummer.
If anyone from AWS sees this, please note this is one more reason your users want the ability to send extra headers. Even if it's only a select few headers chosen from a dropdown list, this added functionality would come as very welcome news.
There is no override to skip and accept an encryption-only connection. Which is what I would have gotten with HSTS as well, because without independent verification the CA system is a lot, but not the mutually trusted third party it claims to be.
I don't believe this is true. Sslstrip would get the site in HTTPS and serve it to you in HTTP, right? Only pinning or hsts would prevent that, HTTPS only servers wouldn't help.
I guess they could mean hsts by HTTPS only, but the end of the article implies otherwise.
>Certificate pinning, though, is limited to Google sites at present
This is also false.
I'd also hope they'd mention something like HTTPS everywhere which also mitigates this.
[0] MITM Proxy https://mitmproxy.org
This would lead to a false sense of security, which I believe would be worse than the status quo.
Please make a favor to fellow HNers and do not upvote ElReg stories. If you find something truly interesting there and want to submit, probably there's a better-written equivalent available on ArsTechnica or other page already.
El Reg have a wide ( tech ) audience. Some articles are for noobs, fine. Like other places they need filler content when there is nothing organic happening.
They also have their finger on the pulse a lot more than stars-in-their-eyes tech coverage elsewhere.
Rather than Daily Mail I think of them more as New Scientist
I use SimpleNote a lot, and don't want my work snooping on the contents. Nothing dodgy, just a little tin-foil hatty. If they do snoop, and I have no mechanism to know when they are, then I'll stop using it.
So SimpleNote use a Comodo certificate ( by inspection ).
How can I personally instruct my browser to reject any cert from a different provider just for SimpleNote.com ?
I'd almost be willing to accept this, because while we do have tons of new mechanisms such as HSTS and HPKP that prevent most of this from happening, and while most big sites have adopted at least HSTS, the same thing certainly cannot be said for every single financial institution and many other sites out there. So I guess there is some truth to the statement that HTTPS is no silver-bullet for public networks ... yet.
It ain't perfectly secure but odds are I'm not the slowest wildebeest.