Personally, I'm for HTTPS connections to things like government websites (which is what this article seems to be mostly about), but against "HTTPS everything" in the way it's going to be implemented.
Personally, I'm for HTTPS connections to things like government websites (which is what this article seems to be mostly about), but against "HTTPS everything" in the way it's going to be implemented.
You being against HTTPS everything, is the same as being in support of MITM attacks somewhere. I am curious when is that the allowable case?
This may be really hard in practice though.
Of course, with non-free software and walled gardens, that might involve some amount of reverse engineering, injecting a CA certificate in a trust store so you can run a MitM proxy, or do something to bypass key pins, but that's never really stopped anyone from finding out what an application is sending on the wire.
You acknowledge that there is a certain amount of traffic that ought to be encrypted, so you really need a solution for all applications either way.
Who's going to spend the time hacking through {random Chinese smart lightswitch clone #8392727} that's sold in small volume?
There's going to need to be a legal "right to decrypt traffic" on black boxes, if we're serious about this.
The suggestion made at https://news.ycombinator.com/item?id=13303650 of terminating TLS at the border addresses this --- traffic on the public Internet is encrypted, but is decrypted in the private local network. In some ways it is similar to a VPN. I run a filtering/adblocking proxy that works in the same way.
My other thought was just mandating a method of loading CA certs onto all IoT devices using an open standard connector. If the owner so chooses.
And then, you are advocating for MITM them, instead of plainly controlling what traffic they create.
If you really want to control them, you should be advocating for open source and the end of DRM.