HTTPS on NYTimes.com
open.blogs.nytimes.com
open.blogs.nytimes.com
NYTimes now joins a small club, alongside the Guardian and the Washington Post.
Here's a dev blog post on the WaPo moving to https: https://developer.washingtonpost.com/pb/blog/post/2015/12/10...
And one on the Guardian moving to https: https://www.theguardian.com/info/developer-blog/2016/nov/29/...
[0] https://security.googleblog.com/2016/09/moving-towards-more-...
They're not trying to force everything over to https, they're just trying to make warnings more sane. And if a page is not secure, marking it as such makes sense.
https://security.googleblog.com/2016/09/moving-towards-more-...
Using https for a local network connection will also be more common, in the case you decide you don't trust the network.
The change is to set it on by default.
Loading mixed (insecure) display content “http://analytics.freedom.press/piwik.php?idsite=4” on a secure pageThe Intercept and Quartz each only publish a few articles per day. Each runs entirely on a single instance of Wordpress. Each covers only a few topics. Each has only a few templates, and simple ad inventory, if any.
A paper like the New York Times publishes many hundreds of stories every day, on almost every topic you can think of. They publish to wide variety of platforms, including print. They have a high volume of widely varying ad inventory. They have legacy content going back decades, in all sorts of legacy formats, perhaps even sitting in old CMS instances on separate servers.
TECHNOLOGICALLY SPEAKING, they are much more complex. Therefore transitioning to HTTPS is more difficult.
None of this is a commentary on the quality or social/cultural value of their content.
Also does anyone know what the new personalisation features are that they mention being able to offer now HTTPS in place?
>Ask any developer at a major media organization what the biggest hurdle to HTTPS adoption is, and the answer is always going to be advertising. However, unless you understand the ins-and-outs of how digital advertising is implemented, it’s difficult to see why this presents a challenge.
from https://developer.washingtonpost.com/pb/blog/post/2015/12/10...
It's also possible that terminating the SSL and then passing through unsecured traffic lower in the stack is not ideal due to where the different parts of the site are hosted - e.g. passing traffic unsecured back and forth between private DC and public cloud.
Note: All speculation based on having implemented SSL migrations at large media companies.
Also, features that are now available once the HTTPS by default on a website, is the AMP, Notifications, HTTP2 (faster loading) and, of course, the little advantage that Google gives to the HTTPS websites.
Not sure what features the NYT is referencing specifically, but Chrome has certain features [like the Geolocation API][1] disabled for pages loaded over HTTP. See [Deprecating Powerful Features on Insecure Origins][2].
[1]: https://developers.google.com/web/updates/2016/04/geolocatio...
[2]: https://www.chromium.org/Home/chromium-security/deprecating-...
If you don't mind 404ing or breaking a ton of your old content, it's probably not too difficult. But if you're the newspaper of record, it's a big deal that URLs live on and continue to work as expected.
But I think you hit the nail on the head -- being the "newspaper of record" means you want to ensure that all your content displays like it did the day it was published.
We could also set a header forcing the browser to upgrade to secure when the resources are in the same domain.
[1] This number is approximate. Could have been less, could have been more; it was a while ago.
edit: I feel kinda bad now that this is the top comment in a thread about something positive the NYT did; if anyone tells me that they've since added online unsubscribe, I will change this comment accordingly.
In most other industries, loyal customers get better treatment. Or it's the same deal for everyone. These sorts of inverted pricing structures may squeeze more revenue out of a few long-term, inattentive customers, but the hidden cost in churn, irritation and haggling is considerable.
Yes, IIRC the reason it was such an exhausting call is that they offered me a series of no less than 3, maybe more, progressively larger discounts. I simply wasn't interested, for my own reasons which are even less relevant to this thread than my original comment was.
If you've ever gotten the discount once, you aren't treated worse than new customers.
The internal incentives (worth an entirely separate post) reward phone reps disproportionately for heroic "saves" of accounts that were about to quit. The big promotion within these call centers is to get to work on the Customer Rescue team.
I don't know why the finance guys haven't figured out that they are rotting out their core revenue by doing this.
[1] http://www.economist.com/help/manageprintsubscription#cancel...
As a comparison (although not directly related), I think this is where Netflix gained traction initially here because despite having an uninspiring catalogue the option of a frictionless cancellation made in it an, almost, no-risk proposition.
I block a lot of sites which started to personalize content in an unwanted way.
I was going to get a subscription for the first time starting in February. I'll have to reconsider that.
I've subscribed and cancelled Hulu+ three or four times when there was a lull in the content. But I'd have no hesitation in signing up again because I remember how hassle free it was to cancel.
Contrast that against LogMeIn which has the same strategy as NYT by the sounds of it (call to cancel, takes 15+ minutes). When I needed LogMeIn for a new project, I looked around for alternatives instead because I remembered how big of a hassle it was to cancel. Ultimately LogMeIn didn't get my repeat business, not due to the financial cost, but the hassle cost of them.
Plus of course word of mouth like this is hugely damaging for these strategies. I won't be getting a NYT subscription now.
[1] Actually I said "earlier this year", which is incorrect as of Jan 1.
In the "My Apps & Games" menu > "Subscriptions" > "NYT Digital Access" > "Manage Subscription" > "Cancel" > "Confirm".
When I want to cancel a newspaper subscription and it's impossibly difficult, I just email them telling them I'd like to cancel the subscription delete the associated credit card. Not my problem anymore
May be different in the US, but if you did that in the UK and they didn't read your email or whatever, you're likely have them sell the debt to a collection agency which will then place a marker on your credit record.
It's then a huge pain in the ass undoing the credit record mark. I still have a default on my record thanks to the cable company here not cancelling our service properly. They even sent an courier to pick the equipment up but despite a trillion emails explaining this they insist they can't do anything about it because they have sold it to a collections agency. What a load of gibberish.
It'd still be nice to have a one-click option, but at least it's a bit easier to do passively than needing to call someone.
I suppose that's the irony of declining business... after a while you can't even afford to take good care of your existing customers, which further accelerates the decline.
It's the best way right now, and it's silly because the news apps have to eat the Apple Tax just because their own internal policies keep me from signing up through them directly.
Source: https://twitter.com/matthew_d_green/status/53504312624809574...
Enabling HTTPS is a benefit even if it's not perfect. The integrity and authentication it provides are alone a MASSIVE benefit (especially for a news site).
Now you'll know that your news is coming from their servers, and nobody else is tampering with it.
Then taking into account that it does provide confidentiality, you get rid of "dragnet" style data gathering and inspection.
You'd need to be targeted by someone who not only has a lot of time, but also is very up to date on the pages of NYT and their sizes to be able to track your article by its size.
No matter what, it's still harder than it was before to snoop on what you are doing.
It's a net gain in just about every single way.
I'm a HTTPS noob, can you explain how or why someone would tamper it on normal HTTP? Who would care to target me and what are the chances that NYT has been tampered with ever before?
How? By being the user's ISP.
Why? To inject adverts.
What are the chances it affected nytimes.com? Almost certain.
Behold: http://arstechnica.com/tech-policy/2014/09/why-comcasts-java... - and that's not the only case of it.
Not only do ISPs do it, but wifi hotspots, dodgy wifi routers, malware on anything in-between, and in some (admittedly rare cases) your government.
And the why isn't just ads. But passive tracking (ISPs have been known to analyze your traffic passively and sell that information), active tracking (the famous Verizon super cookie), "page optimization" which frequently breaks sites, and in some cases malware injection into images, executables, or anything else the bad actor could do automatically.
This is an interesting puzzle. How much data do you need to add to a page before it becomes impossible (or at least, reasonably difficult) to guess which article someone is reading?
I tried to figure out, but then I remembered that I don't know anything about statistics. Oh well, I had fun: https://github.com/ndbroadbent/nyt_privacy
http://gstatic.com (Chrome uses http://gstatic.com/generate_204 , which returns a 204 No Content)
http://www.msftncsi.com (Windows, desktop and mobile, uses http://www.msftncsi.com/ncsi.txt. NCSI is "Network Connectivity Status Indicator")
http://captive.apple.com (macOS / iOS)
because those are likely to be extraordinarily well-maintained and reliable.
Unfortunately sometimes some captive portals allow just this one site through and not the others. Looking at you, United WiFi, which whitelists gstatic.com, but fortunately not msftncsi.com.
Of course this thread makes me wonder if I've been doing it wrong.
Using 1.1.1.1 makes a http request, which lets the captive portal take over, so good job, but you are actually hitting a group that actually exists, and what if they suddenly launch a HTST site on that IP? It might break your method.
I think specifically this url: http://www.apple.com/library/test/success.html
For those interested, learn more at: http://www.dns-sd.org/trailingdotsindomainnames.html https://en.wikipedia.org/wiki/Fully_qualified_domain_name
Why did they do that change, and what would be the advantage for them of an OV instead of a DV certificate?
DNS Name=nytimes.com
DNS Name=*.blogs.nytimes.com
DNS Name=*.blogs.stg.nytimes.com
DNS Name=*.dev.nytimes.com
DNS Name=*.nyt.com
DNS Name=*.nytimes.com
DNS Name=*.stg.nytimes.com
This simplifies deployment significantly.It would often be confusing anyway, as the legal entities the certificate is issued to can be named very different from the brand.
Nonsense. OV is no more secure than DV, just more expensive.
They could however create their own DV cert.
So while it uses the same technology, if you see an OC cert you can be more sure that it's the actual organization and not a cert that just proves that the domain is the domain.
No browsers do anything with OV data unless humans manually take action to examine the certificate. So I'm comfortable saying they offer negligible security value.
(Certificate Patrol's noting of the reverse is a little silly though; why would you flag a change that denotes an increase in security...?)
If so, this change amounts to not protecting user privacy as much as insisting that only the NYT can monetize their users' privacy.
The wifi owners can see that you're reading nytimes.com, but they can also see how much data was transmitted. All they need to do is look up the length of each article, and compare that with how much data the server returned.
Of course, I'm not too worried about hotel owners. I can imagine this technique is already being used by a lot of governments around the world.
"If so, this change amounts to not protecting user privacy as much as insisting that only the NYT can monetize their users' privacy."
The cookie is now hidden from the MITM. Before, not only could they see what pages you see, but they could login as you.
All of that is impossible with HTTPS.
1. https://www.eff.org/deeplinks/2011/07/widespread-search-hija...
2. http://arstechnica.com/tech-policy/2014/09/why-comcasts-java...
3. https://andreasgal.com/2015/03/30/data-is-at-the-heart-of-se...
http://www.theregister.co.uk/2015/02/19/superfish_lenovo_spy...
Lenovo got approximately $250,000 for installing the malware:
http://www.forbes.com/sites/thomasbrewster/2015/02/27/lenovo...
Media websites are constantly-evolving beasts, with a small tech team trying to hack shit up to make them work, and killing older content is never even an option.
At the end, with a limited amount of (mostly human) resources, you kind of have to draw the line somewhere and introduce the change, otherwise you will end up postponing it for possibly months.
They say HTTPS is complex to enable and imply they've been working on it for up to two years. And they finally get it done nine days before Trump.
Some people and organizations are panicking, either about his behavior or that net neutrality is out the window or about some boogeyman. That's why this story is relevant, now, because it's an indication that NYT may feel the internet will soon be a much more hostile environment.