HTTPS Deployment Growing by Leaps and Bounds
eff.org
eff.org
To be honest, I'm glad it's now back-firing with more sites using HTTPS (that they can't hijack connections to), maybe this will nudge the operators into doing things properly - whether that's using WPA Enterprise for username/password auth or using the DHCP option to tell new clients they need to visit an internal URL first to use the internet (no connection hijacking required).
In this “modern” world, it seems past time for governments to start supplying digital IDs. Why for instance can’t every single person have a government-backed certificate of identity once they have done all the usual things that it would take to obtain a driver’s license or passport? And if you can count on a passport being valid for 10 years, why can’t you count on a government CA (say) to continue to validate your certificate for 10 years?
If we're already talking about breaking the current TLS system, a DNS based security (Browsers include DNS keys, DNS hosts site keys) makes much more sense.
Good graces just stop. While this may seem like a step in the right direction and offer a great amount of convenience, one can only imagine how this would be abused by authoritarian powers.
What would be great is for Microsoft to integrate let's encrypt into IIS. If someone feel like voting for that:
https://windowsserver.uservoice.com/forums/310252-iis-and-we...
I don't know. I use Let's Encrypt for the sites where it matters, and I'm all for it with search engines, email clients, anything with a password, etc. But as an engineer who likes to keep things simple, this seems like another layer of complexity borne out of one of those dogmatic 'best practice' rules that makes modern software slower, buggier and harder to maintain than it needs to be, despite our amazing modern hardware.
The fight isn't about a hacker stealing your passwords. The fight is about every single entity on the Internet being hostile towards user privacy with a strong monetary and power incentive to use any and every inch you give them to take a mile. So let's not give them any inches. Encrypt everything using the strongest cipher suites available and the best methods of identity verification we have. It may not be enough, but it's better than giving up and letting the baddies win without a fight.
And to clarify before the inevitable reply points out that HTTPS isn't sufficient by itself to protect user privacy. Yes, I understand that. But it's an important basic building block for doing so.
What, like the largest US mobile carrier injecting supercookie tracking headers into every unencrypted HTTP request? [1]
Yeah, I guess that's only 144 million people.
An attacker could replace your site with anything: ads, viruses, malware, payment prompt. HTTPS also allows you to add HTTP2 support which can lead to faster page loads.
Given that there's a lot of low effort ways to add HTTPS (e.g. Netlify, Cloudflare, Heroku), the question should really be why go with HTTP 1?
Plenty of info on speed out there, here's one example: https://blog.httpwatch.com/2015/01/16/a-simple-performance-c...
HTTPS keeps your ISP, your wifi hotspot, a dodgy router, or anything else from injecting ads and tracking information into your pages
HTTPS ensures that the server and information the user is requesting actually comes from you (and not a shady middleman who might give out bad information or just annoy the user with a slightly broken setup)
HTTPS ensures that content isn't being blocked by a bad government actor based on it's content
HTTPS keeps bad actors from injecting malware into your javascript, your images, even downloaded executables (there is "one click" software out there to inject malware into any .exe download it can find on the network in real time)
HTTPS helps protect against "dragnet surveillance". That doesn't just include bad governments, but also an ISP which might build a profile on you based on your browsing habits.
HTTPS treats information as "secure by default". You won't always know what is and isn't "private" to each person. "phrasegenerator.com" might just be a fun game to you, but to someone else it might generate a phrase that could get someone fired, or worse, based on the content of that phrase.
And using HTTPS everywhere means that it's harder to identify "secure" information from "insecure" information. Breaking one HTTPS connection one time for one person and one server isn't "easy", but it's not impossible. Breaking HTTPS for all connections to everyone every time for every server becomes practically impossible.
The overhead is next to nothing, the complexity mostly abstracted away, and with stuff like Let's Encrypt the "maintenance factor" is quickly getting reduced to "fire and forget".
There's no excuse to not use HTTPS any more in my opinion.
I suspect this is the main reason Google is so gung-ho about "https everywhere". Because of the popularity of GA, adsense, Double Click, and Google local caches at every ISP...they already have near global tracking. Closing the ISP MITM hole ensures that nobody else does.
Of course, "https everywhere" is good for other reasons, so not complaining...
Next PCI DSS will require most services to be using (and not honoring lower then) TLSv1.2; i'm not sure about what to do when (not matter of if, but when) that is considering no longer secure, TLSv1.3 isnt ready yet from what i understand.
Now that i write this i wonder, are there btw server/client solutions that utilize PGP? E.g. send requests via encryption with public pgp key server and response back to client with public key of client?
Then there is the whole MUTANT BROTH program, which maintains a database of billions of intercepted cookies, and can be correlated with other traffic to identify particular engineers behind a corporate firewall for targeting and exploitation, as was done with Belgacom [1]. To thwart such an attack requires encrypting any request that contains a cookie (or, conversely, never accepting a cookie from an unencrypted site).
The problem is that it's really hard to make judgments about what's "security sensitive" for someone else.
[1] https://theintercept.com/2014/12/13/belgacom-hack-gchq-insid...
If you're a generic human being and want to do something like create a little blog or share some artwork online or whatever, any little extra barrier or complexity is just a big pain in the butt that discourages you from doing that. I think this trend towards https is a factor in subtly encouraging people to just sign up up for one of many walled gardens out there in Facebook/Tumblr/Twitter/whatever because it's a lot less work and that's a bad thing for a free and open web in the long run.
That's a problem of GitHub, not of TLS