HTTPS adoption has reached the tipping point
troyhunt.com
troyhunt.com
The statistic is that 50% of page loads are HTTPS - the majority of those page loads are going to be visits to a very small subset of extremely popular (and well-resourced) sites, so this stat gives no indication that the remaining 50% is or will move to HTTPS anytime soon.
The real tipping point will be 50% of unique domains visited being HTTPS. And a more interesting statistic would where that figure is now, and trend data on that. I wonder can that stat be extracted from public Mozilla data...
This allows them to intercept the traffic by shunting the plaintext off of the proxy to another system. Of course, it's plainly obvious to you, the endpoint, that this is going on because have to trust that compromised CA on your device to access the site. They'll, of course, helpfully offer instructions about how to do this and require it to be pre-installed on systems.
But if there's no other way to access any HTTPS services? Lots of people will do it.
The first line of the article:
> HTTPS adoption has now reached the moment of critical mass where it's gathering enough momentum that it will very shortly become "the norm" rather than the exception
This statistic doesn't logically follow through to that conclusion in any way.
I am hopeful that HTTPS is becoming the norm, but this particular stat just doesn't really give any insight either way.
The new warnings for password fields are a promising step however.
1: https://blog.chromium.org/2016/09/moving-towards-more-secure...
Browsers are going to show scary warnings for these (indistinguishable to the average user from any other warning), and then stop loading them altogether, and the sites will die only to be reborn (if at all) on facebook.
Sorry, can you explain? (Not playing "gotcha", I really don't understand.)
Going forwards I expect we'll see more webservers with Let's Encrypt-by-default, so it's a limited-time problem; it shouldn't affect many people after the initial shakeout.
On NixOS, enabling LE is no harder than putting "services.nginx.virtualHosts.<hostname>.enableACME = true" in my configuration file.
Planning to do a follow up to get a trend. Also some deeper analysis is needed: Many of the HTTPS sites just 301/301 to HTTP for the same domain, and often to other domains. So while those are websites that speak HTTPS, they aren't really HTTPS sites.
The long tail is still going to be large in cumulative terms
Certainly a far cry from 15 years ago when I used to go through the Spanish Inquisition to get an SSL certificate, not to mention the cost. LetsEncrypt has been a game changer.
So too has AWS, with their Certificate Manager. I've been rolling out their own issued SSL certs to our various Elastic Beanstalk instances as they come up for renewal. Saving a pile of money, but more importantly, TIME, doing this.
For me personally, that is the tipping point - making SSL installs on server a couple of mouse click and less than a minute. Not surprised that it is becoming increasingly popular given this.
This is by the same author, and there are critics that could be made against it. In some cases it is faster it seems.
HTTP/2 will be mainly a large win for short requests, where it can avoid the large overhead of creating additional TCP connections and make header exchange more efficient.
Typically browsers that support HTTP/2.0 require the use of TLS, so with a little mental gymnastics he's claiming that HTTPS is faster.
Edit: Apologies, I agonised over the wording for so long that 4 other people answered before me.
Now, in the real world, HTTP/2 is going to mean TLS - which is good, so yes, HTTPS will be faster in that case.
I referred to Troy's assertion that "HTTPS is faster than HTTP", which is at best an incomplete statement and to some people completely misleading.
I don't know any other porn sites that have gone https, definitely not the big ones that dominate the market such as youporn, porntube etc.
There's an RFC for a way to add this to DHCP https://tools.ietf.org/html/rfc7710
They only really exist where people have no other choice (e.g. hotel). They're often broken, or unusable on mobile devices with tiny UI. Captive portals are an abomination and misuse of technology, not to mention a terrible user experience. And any brand using a captive portal just diminishes my view of the brand.
But, there has to be some reason that these exist right?
To get rid of captive portals, there needs to be this functionality in the underlying protocols:
- Requiring Terms of Service
- Showing a special site from the service provider (like the page Starbucks takes you to after "Accept and Connect")
- Selecting what kind of connection you want (like at airports and hotels where there's free and paid)
- Login to some system the service provider controls (also airports and hotels w/ paid plans)
- ... and, potentially other things I haven't seen
Edit: Somewhere else in this thread, kelleboo mentioned this [0]
Not really - I don't think implementing legal considerations into technology is the way to go. Mainly because laws vary by country and laws also change independently from technology.
For example, in Germany, EULAs only valid if agreed on at the time of purchase of the goods or service. If presented after purchase, even if you have to click some "I agree" button, they are not valid. (And even then, they can't contradict German consumer law.) I don't believe anybody has sued because of WiFi, but then the question becomes when does service start? When you connect, or when you click accept?
Keep in mind that some devices like Nintendo DS' or Kindles can't use captive portals, better implementations of portals recognise these devices and let them connect.
In reality, what does the ToS really way, anyway? Don't do illegal stuff - but that's illegal with or without ToS. For free WiFi, you only have X amount of traffic - well, it's free WiFi, there's no obligation for for service.
(Put simply, EULAs and ToS' also need to die - but that's a different discussion.)
Billing is more interesting. One argument is it's 2017 - should we really encourage billing for basic WiFi when bandwidth is cheap? One solution could be to give users x amount for free, and only if they use all that use a captive portal. It's not ideal, but at least it doesn't happen right at the start. You could also simply have different SSIDs for paid and free.
I think that's totally fair to say. But just know that the immediate answer from Starbucks or whoever at that point is "Ok, then we'll continue doing what we have to do".
With the ToS/EULA, I think it's really a cover-all protection measure. So, if there's something that the user is doing that is illegal, the service provider is not liable for the user. For example, I go to Starbucks and torrent Star Wars; Disney sues Starbucks for facilitating me or whatever.
But I think your last point is where the argument breaks down. Yes, WiFi should probably be free at this point. But, there are tons of reasons that are valid (even marginally) someone would want to have someone connect to some website before connecting to the rest of internet. Without providing some way to do that, the terrible hacks will continue.
Try visiting: http://clients3.google.com/generate_204
Is there any plausible scenario whereby visiting such a basic site without any forms or data collection over HTTP is in some way a disadvantage to HTTPS?
They're not malicious, but could easily be. You can intercept and inject anything you want if you control the network with HTTP. Also, e.g. spoofing an unsecured WiFi network is pretty easy. Even on wired networks, do you know what path your traffic is taking? With HTTPS, it doesn't matter.
There have been many recent cases of ISPs inserting advertisement on sites like yours. From there to malware it just takes a more ill intentioned actor.
I don't think script kiddie level attacks happen very often, because there are many easier avenues if you want to mass attack people. But MITM attacks can be very valuable for targeted attacks, because with it one can corrupt peers that your target trusts.
My flowers are actually hosted on Amazon so it's already automatically both http and https. I don't generally share my photos too widely, but since you asked I'll share my flowers...
Please install PanicMode browser extension for Chrome (https://chrome.google.com/webstore/detail/panic-mode/lamdafc...) and try to surf the web for a day. You will know what I mean as soon as you go through this experiment.
Disclaimer: I am the author of this extension. I wrote the extension for personal reasons and it is very simplistic in nature. If you turn PanicMode on it will replace every outgoing http:// url with https://. It does nothing else besides that and unlike HTTPS Everywhere it has no exceptions list or special handling of the top 100 sites, etc. The site you are visiting should either support https:// or it will blow up in your face, which is exactly what happens 90% of the time.
Edit: Besides just because Firefox is seeing more HTTPS traffic means nothing if all the traffic comes from Facebook, Google, YouTube and a few others. Yes, there is more traffic and yes it is encrypted but does it really say anything about the state of the web? Someone needs to put this data out to make it clear.
https://addons.mozilla.org/en-US/firefox/addon/http-nowhere/
The prefs.js syntax is, noscript.httpsForced "¤.cn\n¤.ru\n*.uk"
Edits: ¤ characters are asterisks.