Also, those HTTPS numbers are amazing!
* Over 68% of Chrome traffic on both Android and Windows is now protected
* Over 78% of Chrome traffic on both Chrome OS and Mac is now protected
* 81 of the top 100 sites on the web use HTTPS by default
Also, those HTTPS numbers are amazing!
* Over 68% of Chrome traffic on both Android and Windows is now protected
* Over 78% of Chrome traffic on both Chrome OS and Mac is now protected
* 81 of the top 100 sites on the web use HTTPS by default
Personally i am very concerned about how much power Google has over the web - all it takes to change millions of how web sites work and look like is a random decision by Google.
What bothers me even more is that most people do not seem to care much because they happen to agree with what Google is doing (so far). However i think that sites should make decisions on their configuration, layout, mobile friendliness and other things because they want to, not because they are forced by Google through taking advantage of their position and biasing what people see towards what they believe people should see.
I do not like that Google basically dictates how the web should behave.
(actually it isn't only the web, but also mail - just recently i had a mail of mine end up in the spam folder of someone else's GMail account because who knows what of the 1983847813 things i didn't configured exactly as Google likes it in my mail server... and of course the "solution" that many people present to this is to hand all my communications to Google)
What do you think is a random decision?
> However i think that sites should make decisions on their configuration
It's OK when they have ideas what they are doing, but that's not always the case.
Before my trip to Kaua'i I googled some dive shops on the island to book a scuba diving trip. Every dive shops on the island seems to be using the same vendor to process online order of the reservation, which has the same form to input credit card number, and has some text around it saying "it's secure". They are not secure. They are on HTTP: https://twitter.com/fishywang/status/895133987525476354
<iframe src="https://fareharbor.com/embeds/book/seasportdivers/?full-item...
Most people don't need HTTPS for most sites. I think it's safe to say most security and privacy breaches are due to poor practices on the back end or by end users.
Protecting people who aren't at work but are using a potentially hostile network (public WiFi, etc.) from their own device is certainly a legitimate concern.
I've inspected my own HTTPS traffic a number of times using it including e.g. traffic from e.g. iPads where my Desktop was effectively acting as "the edge device". Of course, this is more for debugging than aggregate statistics/monitoring...
This won't let you inspect traffic secured via certificate pinning without additional reverse engineering to figure out how to replace the pinned cert, but it'll work fine for vanilla HTTPS / generic CA based stuff (e.g. all browser traffic.)
Replacing a cert doesn't get around cert pinning. That is the exact use case that cert pinning protects against.
For public certs: Yes, but that would only produce the desired effect if the site hadn't yet been pinned, and this was a first connection, or in the case of the pins having expired. In other words, the pinning can only be stripped out if there is no pinning already in place on the client.
However, this will soon be a moot point, as Chrome removes pinning in favor of cert transparency. This will reopen this security hole in browsers simply trying to be secure within captive portals and other insecure networks. Tor has pinning that would extend from inside the portal to outside, so that may be one option, but I don't yet know how sturdy that is.
Google is not doing this without interest, but I guess it overall is beneficial for us as well...
The hypocrisy here is amazing, too, because while pushing HTTPS, Google itself is actively following everybody around, tracking everything they do online.
The obvious one is that it makes your traffic hard or impossible to sniff.
What's often overlooked is that it also makes your session highly resistant to tampering by 3rd parties. These parties include:
1. Anybody who might have access to your home WIFI network.
2. Your Internet Service Provider. There's been plenty of documented cases where ISPs have injected 'harmless' HTML.
3. Any number of bad actors if you're using any kind of public WIFI.
4. National actors. That's the NSA in the United States, where we have clear evidence that they have been capable of intercepting unsecured connections and injecting unreleased attacks into targeted computers.
This is not tinfoil hat stuff.
The benefit of https is undeniably greater than the cost.
I'm not crazy about how Google throws their weight around in a lot of cases either. But in this case, I think they're doing the right thing.
Three things not two. Confidentiality, Integrity, and Authentication.
An ISP is by definition a man in the middle, and unless the user checks certificates for every page and resource they fetch then the ISP can inject their own certs and monitor traffic if they really want to.
And most of the time national actors like the NSA will have better ways of getting the information if they need it
In any case, I don't think "an ISP could inject their own certs very easily" is a fair characterization unless you put it on the same footing as "anyone with your email can get people to install malware easily".
As a concrete example, Lenovo were caught.
The article is about one practical measure that a browser maker has taken to improve the piece of user-facing software that they are responsible for, and some users of that software are applauding this improvement.
Having said that, I do accept your over all point that there is a lot of other work that still needs to be done in securing the web. As you suggest, that's not going to be easy, but let's not fail to fix the things that we can fix already.
If I'm passively browsing I don't really care too much. If I'm submitting forms, or working in a authenticated session, that's a different matter of course.
And as easy as it is to get a certificate these days, what does it really prove? It stops 3rd party snooping, but then again so does a self-signed certificate.
Let's Encrypt offered three of the Ten, but one was discovered to be flawed due to the way some major bulk hosting services are configured, so that leaves two (of Nine, since in practice any implementation of the Tenth Blessed Method is flawed the same way).
Even flawed Blessed Methods are far superior to the checking (basically none) we can reasonably expect from a normal person using a web browser. But still, improvements upon the Blessed Methods are a topic of public discussion, if you think you genuinely have a better way you should definitely let the CA/B Forum or m.d.s.policy know about it.
>It's just too easy to get them to think they really mean anything.
I'm not sure what you mean by this:
1. Are you saying that there is a vulnerability where you can get a valid certificate for a domain you don't own?
2. Do you mean the fact that valid owners of a domain can get a certificate easily?
If 1, please provide more info. If 2, why is that a bad thing?
Whether an EV certificate should do much more for trust than DV is a matter of some debate.
https://tools.ietf.org/html/rfc6108
Nobody is affected by this?
If the connection were HTTPS they could simply block it or redirect it wherever they want to give the same message. An ISP will always be able to MITM the connection.
The only thing?
I can think of four others off hand. That said, the “only” thing is pretty important in itself.
You know what people get bitten by? Hacked servers where the whole website is under a phisher's control or malicious website which downloads malware to your machine or sells your data (eg, Google, Facebook).
Maybe my knowledge is lacking, so please tell me what those 4 things are that you're being so elusive about. I suspect they are also as unlikely as MITM.
I'm not trying to protect myself from a targeted attack. I'm trying to protect myself from the enormous amount of scummy behavior in this whole industry. When I connect to my bank, I want my data to be secure not only against malicious activity, but negligence and incompetence. This is the threat model that HTTPS-Everywhere protects against.
Sure, people get bitten by viruses and phishes. But let's fix things one step at a time.
What bank do you use that doesn't use https already? Maybe it's time to change your bank rather than force every website in the world to switch to https.
How do you know? What is your groundless, evidence-free assertion worth to you?
> Nobody cares enough about me to do that.
I have detected Firesheeping on coffee shop networks in the past. Guess somebody cared about all the people in there, huh?
The conflation of Google using information collected about you in aggregate to provide advertising services and man-in-the-middle attacks on clients is dishonest, disingenuous, and at this point downright malicious. Stop.
Usually shitty public WiFi providers injecting ads.
Exactly. In the overall threat landscape that computer users face using HTTPS for cat videos and blog posts is meaningless.
Everyone who needs HTTPS already implemented it and any individual user who actually cares about security can use a VPN.
There hasn't really been much of a span where there wasn't a de facto 900 Lb gorilla browser that threw its weight around. I think a lot of us watched this happen, but the various charts on this page are instructive:
https://en.wikipedia.org/wiki/Browser_wars
It appears that somehow the browser market trends toward an unstable near-monopoly of sorts, at least so far.
So, meet the new boss, same as the old boss. At least https everywhere is a long-term public good that they're willing to take grief over forcing. It beats some of the other unilateral changes various once-dominant browsers forced.
It's not random and that it just might serve security is a side effect.
It is about competitive advantage over other Ad Networks which might not implement HTTPS for AdSense. It is about raising both monetary and technical cost of server setup to make Google Cloud offer look even cheaper. It is very self serving.
And by that you mean?
I'm a fan of Hardenize. I like using that site to help people understand what needs to be done.
The especially frustrating thing is that there's no way to find out why you've been binned. Even my friends who work at Google can't find out for me, much less get me whitelisted.
This doesn't change the problems of unreliable email because mail services are too aggressive, unfortunately.
We recently got a bounced mail (not dumped in a spam folder, actively rejected) from a major university, telling us that the message looked like unsolicited bulk mail. The message was sent directly to a specific single customer in response to a purchase they had just made, contained information that we were required by law to provide to them, and was sent from a reputable host with things like SPF properly set up. That is simply broken, and it is 100% the fault of the mail service admins at the university.
Required maintenance for a simple, static https site: configure let’s encrypt and keep the cron job running.
Big difference? Not for some, but it sure is something that offers very little value for very many site owners. Even the top 100 sites are only at 80% https by default, and they do it for a living!
Because it's not meant to offer value for a site owner, it's meant to offer value to the user.
When I type a password on your website, I'm the one that has the most to lose there. When I type my credit card or other personal information into a site, I'm the one that will need to spend time and money getting control of my information if it was stolen.
When I am browsing the web and ads are being injected into the HTTP request, or my ISP is dragnet datamining, or a compromised router is injecting malware into every page, I'm the one that loses, not you.
The argument that an insecure website is easier to maintain than a secure website is like saying "a car without airbags is easier to work on". The extreme vast majority don't care about how easy it is to maintain the site, they care about their privacy and security.
And your counterpoint is needing to download and run some open-source software once a month (or automate the process and never touch it again). A few years ago that would have been a much larger list, but developers were listening to the complaints, and realized that the only way to a fully secure web was to make this process easier, so they did!
It's easier than ever to enable HTTPS on every website, and in the vast majority of cases it's a net improvement for users.
And privacy of information going from your browser to the internet is only half of the equation. What about privacy about what you are viewing?
I don't want every single router between my computer and the server knowing the full contents of the pages I'm choosing to view, or building advertising profiles on my habits, or even knowing what device type, browser, OS, and more I'm using.
Would a self-signed (I'm not sure this is the right terminology) cert be sufficient for this?
That way if someone MITM'd you, you would see that the cert changed, right?
But I guess if the path you use to the website is always the same, then if they MITM'd you the first time you accessed it, you wouldn't be able to tell?
Hmm, I guess that probably isn't enough then.
Is there really no good way to serve public information from a website that doesn't require periodically updating one's cert, and without risking MITM'ers changing the content?
I guess if the client already has the hash of the content, but that isn't very convenient.
Huh.
I guess example.com needs https then?
They don't use HSTS to force it, because example.com isn't meant to anything but an example.
Yes, but browsers make that MUCH more scary than surfing insecure (not https) sites.
I can publish my personal CA certificate and ask you to trust it. This is hardly different than how I prove myself to Lets Encrypt.
These days Let's Encrypt uses a "multiple view" approach in which more than one physical location in the world hosts Let's Encrypt systems (although only their US West Coast location contains the actual CA) and so they can check that things appear the same from more than one angle, you can't just take over the ISP they're getting service from in California and leverage that to get anything you want. If the views don't agree (e.g. you pass a Let's Encrypt validation from Paris but not from San Francisco) then your application is denied automatically.
Now, the next layer above is also interesting. Who checks Let's Encrypt and other public CAs are doing their job? Fortunately Mozilla are on the case again, all major Trust stores say they enforce the Baseline Requirements which explain how a CA should do its job, but all except one make decisions entirely in private. Or maybe they just bin all the complaints if the CA pays them a bribe? Who knows. Mozilla acts openly in public, you can (and indeed your insight might be valuable, so please do) help oversee the Web PKI in their m.d.s.policy group.
Problem is that browser warnings are sometimes false. Self signed certificates are not unsecure, the underlying encryption is still the same. The "unsecure" only applies to the CA, but that is not clear in the warning.
Browser warnings aren't false, you're reading of them is false. Read around on badssl.com [0]. The self-signed warnings in chrome say:
>Attackers might be trying to steal your information from self-signed.badssl.com (for example, passwords, messages, or credit cards).
And when you click advanced chrome says:
>This server could not prove that it is self-signed.badssl.com; its security certificate is not trusted by your computer's operating system. This may be caused by a misconfiguration or an attacker intercepting your connection.
It says nothing about the encryption being bad, I don't know where you got that from. What it does say is that Chrome has no way to validate that the site you are going to is actually the site in the address bar. Encryption is pointless if anyone and everyone knows the password (oversimplified, but you get the point). Encryption without Authentication is as secure as normal HTTP.
No it is not wrong, even your confusingly worded sentence there is still fully correct.
Security (or encryption, or any other synonym you can come up with here) is made up of 3 (well technically 4) parts:
* confidentiality
* integrity
* authenticity
* (and technically non-repudiation, but that doesn't really apply here)
self-signed HTTPS certificates only provides 2 of the 3 (confidentiality and integrity) and it's that last one that is most important (authenticity), because without it you don't know who you are talking to. It could be your website, or it could be some asshole down the street pretending to be your website, you have literally no idea.
You say it's misleading, but it is you that is misreading and misunderstanding the concepts. Encryption without authentication is like encryption without a password. Utterly pointless.
Just like my analogy, AES encryption with a password of nothing is "unsecure", and no matter how much you try to argue that it's still perfectly secure, you are wrong..
Just like this, the AES is pointless when ANYONE can set the password (or in more correct terms, when anyone can create one with the user in a DHKE). If you can't tell that the server you are talking to is actually the server you meant, then AES does fuckall, because the man-in-the-middle is the one that is setting the password!
You are doing the equivalent of telling me how secure your new house door lock is, while wiring it up to always unlock when someone rings the doorbell... All the security in the world won't help you when you give everyone a way to bypass it instantly.
Luckily browsers will show you the warning saying that page is insecure, and give you the option of going there anyway after you have validated that the cert is the same.
So don’t use a shitty ISP that tries to MITM you.
Problem solved. How is that even controversial?
Rather than the hospital supplying any kind of proper authentication, they MITM the first connection to their WiFi, and logged your IP address as your user. They also required you refresh that connection every half hour or so.
There are a lot of people doing things in really bad ways.
We can't fix all of them, and often we don't have a choice about interacting with them.
"keep a cron job running" sounds like it you're running the cron job by hand.
>Even the top 100 sites are only at 80% https by default, and they do it for a living!
That's entirely separate from your "simple, static site" example and yes, rolling any sort of large change out to a big site is a big deal, and if there isn't business motivation to do it it likely wont happen. Google is providing everyone a business motivation by threatening to point out to users that insecure sites are insecure.
Cron jobs fail sometimes. You have to monitor them, investigate why they failed, fix the issue, and rerun them.
Web servers fail, too, but with shared hosting, it's mostly not your problem. And shared hosting providers are still trying to charge an arm and a leg to manage SSL certs for you (because it's a nice high-margin business for them).
Eg tools like cPanel have built in support for it now.
2. Let's Encrypt will send you an email if your certificate is going to expire in a month. This will normally never happen, since it is continuously renewed.
You now have to configure e-mail on your small server to actually work (and not get immediately eaten by spam filters of your personal e-mail provider).
Really?
But I don't think most site owners should be doing even that much. They should just pay for static hosting, which is cheap and ensures somebody else will keep the server, os, and cert all safe.
ubuntu + nginx worked fine for years without much maintenance, but I've spent so much time reconfiguring things when something breaks (and it is really clear when something a renewal fails... thanks HSTS).
Things that used to be simple, like putting setting up a subdomain (need to get a new cert and reconfigure the cron job now) or pointing at a websocket (can't point directly at node since that's not secure, needs to pass through nginx now) consistently take hours to do now.
I mostly do data analysis and front end work; mucking around in nginx config files is something I would have been happy never experiencing. It sucks that it's harder to host your own website now.
It's really hard to imagine it getting much easier.
Advantages are that it is free and zero maintenance, however nation or network providers can intercept between cloudflare POP and my server. I'm ok with that for my situation.
Cloudflare may have made it more common for the most basic kind of site (with their easy setup and free tier) but at the same time most of those sites probably didn’t use https anyway.
The reasons this has been done are performance (specialized hardware/separation of concerns) load balancers/firewalls needing to decrypt to route/enforce policy (that doesn’t need to imply termination but it often goes hand-in-hand) and protecting keys from your app server (think of it as like an HSM - if your app server gets compromised you probably don’t want the TLS private key to be leaked. Again you could reencrypt with a different key but often this hadn’t been done.)
The threats for last mile network fuckery (e.g. consumer ISP) are quite different then on the backend. Google has to worry about nation states messing with their networks and so they’ve had to reengineer end-to-end encryption within their network. As an end-user you just sort of need to accept that this isn’t within your ability to control or know.
Even still, the difference between this and e2e encryption isn’t something an end user is really equipped to evaluate IMO. The threat model is practically different vs e2e no-encryption.
Cloudflare also supports reencryption over the net which is useful if your hosting provider supports HTTPS but not via a custom domain (e.g. Google clouds GCS (S3))
With services like Cloudflare, you can terminate TLS at CF, and then proxy over the public internet to the server that actually serves the page, which I think defeats a lot of the purpose of TLS, and I can never know ahead of time when I request a page of HTTPS if this will in fact be what's happening.
That said, using certbot made it so painless I just started doing it at some point for everything I run and I only once had a small hiccup configuring a renewal-hook.
This argument from cost doesn't seem like a compelling one to me. It's not money being thrown away, it's delivering real added security.
Then not just one but two huge tower blocks in London burned down. So how about that, suddenly maybe tower blocks _did_ need sprinklers after all. Shame about all the dead people.
It's better to use a content-hosting service, and as a bonus you don't have to keep cron jobs running in order to get TLS.
Mozilla already does this with Firefox: https://support.mozilla.org/en-US/kb/insecure-password-warni...
Doesn't seem like Chrome's planning to do it that way though.
Maybe Chrome would be up for it at some point in the future as HTTP form submissions become rarer, though I don't know how they made this decision.
Edit: Amusingly, even though I normally use Firefox, I haven't noticed this UI element recently because I'm so conscious of HTTPS—working on Let's Encrypt and support for it—that I rarely even try to enter information into a non-HTTPS site in the first place. :-) (so I might not be quite the target audience for this notification)
The whole point of Google's https crusade is to secure users from ISPs profiling their browsing activity, which for them is about eliminating the competition because they still monitor and track everyone and so if they knock the ISPs out they solidify their monopoly position.
HTTPS is not bad but Google's motives (in the context of their business model and monopoly position) are and that gives some people pause.
Even if that's Google's motivation, I'm OK with the end result. I already use a VPN on my iPhone when on LTE because Verizon's been caught sniffing and manipulating traffic a few too many times. At least I can (and generally) do opt out of using Google's services, so I genuinely appreciate them helping me out of out Verizon's unwelcome inspections.
You are surprised to see people expecting more monopolistic behavior from the biggest monopolist on the web?
I have bridges for you.
In theory, restaurateurs would hate health inspections, because they're intrusive regulation with no direct benefit. But they have a lot of indirect benefit, in that the safer people feel going to restaurants, the more likely they are to go out to eat.
Similarly, the safer the web is, the better off Google is, because people do more things on the web. That does benefit them, sure, but I don't think it benefits them disproportionately, let alone harms other legitimate competitors.
The US is in a very long restaurant boom: https://www.theatlantic.com/business/archive/2017/06/its-the...
And I don't think it's an accident that goes along with a large decline in food-borne illness rates: https://www.cdc.gov/foodnet/pdfs/FoodNet-Annual-Report-2015-...
The restaurant industry is one place where self regulation works surprisingly well. Think about your own experience, as it's true for just about everybody. When you choose to go out you most often go to one of a handful of the same restaurants. What happens if you get sick at a place? You're probably not going back there. And you're also probably going to tell your friends. If you're particularly upset you might even post some less than friendly reviews of the restaurant. That restaurant, with one mistake, converts a high value customer into a one man image destruction machine. And now let's imagine it wasn't a one off, but this restaurant actually makes a significant number of people sick - even if on just one a single day. They're pretty much dead.
All the rules and regulations make it much harder for people to start new restaurants. In most states you're looking at several permits and associated educational courses just to be able to even call yourself a restaurant. And then don't forget to fact in the fees for the permits, the fees for the classes, and plenty of more fees on top of that. Basically you end up having to pay the government a whole lot of money just to be able to sell the food you've probably already been making your friends and family for years if not decades.
And this leads to utterly ridiculous scenes like this [1]. How dare a man try to sell some hotdogs without asking the government for permission. Time to take all the money out of his wallet, fine him, and probably schedule a court date too. By contrast, you can be completely certain that 100% of McDonald's franchises have every single government fee and permit covered inside out. But that does little to stop people ending up with their food being mishandled, and in some cases intentionally. The big thing you'll see in industries with heavy regulation is a trends towards centralization. Here [2] are some actual data on this 'golden age of restaurants', though the ridiculous number of chains itself is more indicative of the issue than a recent slump.
[1] - https://streamable.com/3dvge
[2] - https://www.npd.com/wps/portal/npd/us/news/press-releases/20...
> You're implying that the primary reason restaurants aren't making people sick, en masse, is because of rules and regulations.
No. The primary reason restaurants aren't making people sick is good hygiene all along the food supply chain. But good hygiene isn't easy. It gets harder the more industrial your operation gets. And short-term financial incentives cut against it, especially when you're working at scale.
I will happily eat from one of the probably-unlicensed hot dog carts in my neighborhood because a) I can inspect their kitchen, b) I see them around and so can know who's got a track record, c) I can see who's moving a lot of product, and d) they just can't carry a lot of inventory.
But I won't be nearly as casual with restaurants, because there is so much more opportunity for poor hygiene to impact food. Happily, I live in San Francisco, a city with vigorous restaurant inspection, one where the scores are posted physically in every restaurant. Here, I'll try new restaurants at the drop of a hat, because I'm not worried about shitting my guts out, something that happened to me repeatedly in my third-world eating adventures. My folks, who lived in Mexico for many years years, had a complicated set of heuristics around where to go and what dishes were most likely to be safe. Nobody in SF does that.
Your theory is that this is terrible for restaurateurs trying to do new things, but San Francisco is one of the best food cities in the world, with new, bold things opening frequently and often doing quite well. Unregulated sanitation strongly advantages chains, because people know they're getting a safe product. Strongly regulated sanitation enables entrepreneurs, because it removes safety from consideration when looking at a new restaurant.
People opening restaurants here complain about many barriers, but I've never heard one grumble about health code regulation. It's mostly what good cooks do anyhow, so they're happy to be held to a high standard, especially if it disadvantages competitors who would otherwise be cutting corners.
Arguably the biggest issue with the regulations is that they're overreaching and extensive to the point that if somebody wants to find a violation, they probably can. And many have very little positive effect. In California the 'CalCode' [1] for food regulations alone is 188 pages of random rules, which regularly change. And that is not an all inclusive document. It regularly references not only itself but also other sources. If you actually put all the rules in their verbose and clear form together, it would likely exceed a thousand pages. And you get these dense rules like:
"FOOD prepackaged in a FOOD FACILITY shall bear a label that complies with the labeling requirements prescribed by the Sherman Food, Drug, and Cosmetic Law (Part 5 (commencing with Section 109875)), 21 C.F.R. 101-Food Labeling, 9 C.F.R. 317-Labeling, Marking Devices, and Containers, and 9 C.F.R. 381-Subpart N Labeling and Containers, and as specified under Sections 114039 and 114039.1. [...Skipping several more lines of rules, this for this single rule...] Except as exempted in the Federal Food, Drug, and Cosmetic Act Section 403(Q)(3)-(5) (21 U.S.C. Sec. 343(q)(3)-(5), incl.), nutrition labeling as specified in 21 C.F.R. 101-Food Labeling and 9 C.F.R. 317 Subpart B Nutrition Labeling."
And that's just one segment of the regulations. If by some miracle you manage to obey every single rule down to the dime in the Calcode, there's then hundreds of other pages of rules and regulations you need to obey. And as mentioned many of these things are completely arbitrary. How deep a sink do you think you need to wash the utensils in a food cart? Would 9 inches do? Obviously that'd be way more than enough, yet that'd be a violation of CalCode giving them sufficient cause to find and/or shut down your business. Some politician somewhere at some time decided all sinks must be at least 10 inches deep. Why? No good reason. Instead of creating common sense regulation, rules and regulations inevitably converge on these obtuse rules. Instead it could be that all utensils and instruments used in food preparation need to be able to be fully cleaned on site. But that'd be too logical.
This is all an enormous burden on individuals starting businesses and serves little purpose other than ensuring we're left with chains and perhaps your 'bold' restaurants, which I assume boils down to a euphemism for overpriced outlets primarily targeting yuppies. It's much easier to afford the full size legal team necessary to navigate all this mess when you have a 4 figure markup on your product!
[1] - http://www.emd.saccounty.net/EH/Documents/Calcode2017.pdf
Fundamentally, I think you're just making a lot of this up to suit your ideological views.
For example: "Would 9 inches do? Obviously that'd be way more than enough, yet that'd be a violation of CalCode giving them sufficient cause to find and/or shut down your business. Some politician somewhere at some time decided all sinks must be at least 10 inches deep. Why? No good reason"
Do you have any data demonstrating this sink issue? I'm betting no. Having cooked commercially, though, I can tell you a deep sink is absolutely necessary to clean well. Is the numeric measurement possibly a little arbitrary? Sure. Most are, but that's better than just "have a pretty deep sink", because you want to install that sink once. You don't want to rip it out later when an inspector says, "Not deep enough, try again."
The people I've met who work on regulatory issues are smart, sincere, and often really want to make things work for users. That's especially true for business regulation, as business owners have the political clout to complain.
I note also that you're energetically conflating restaurants, prepackaged food facilities, and food trucks. Those are all pretty different businesses.
Another example: "This is all an enormous burden on individuals starting businesses"
I doubt it. I know people who have started restaurants, catering companies, and a premade food company. None of them ever have mention this as a particularly big burden. They complain about all sorts of other things. Staff, customers, competitors, and definitely prices from suppliers and landlords. Never one grumble about safety regulations.
As an aside, the reason that many regulations don't seem "common sense" is generally that some asshole found a way to do something bothersome, so they had to add another regulation. For example, in LA people started to effectively run dodgy used-car lots out of public parking on major streets, inconveniencing both people who wanted to park and merchants who wanted customers to park. Last I heard they were looking at a variety of regulatory solutions, none of which would seem "common sense" unless you know the problem. It's the same deal with building codes; many regulations don't make sense until an expert tells you what's up.
And the same applies with software, really. Look at all the things people have to do to make secure software. Many of the rules make no sense unless you have an attacker in mind.
So given that your basic take seems to be, "I, an internet random, think some regulations I know nothing about are dumb," I guess my answer is, "Ok, buddy. Thanks for sharing."
Another example from Google would be them preventing you from running plugins on Chrome that were not from the Google store. Yeah, it can be spun to be about protecting users from malicious plugins but it also enhances their control over their users. Incidentally, they decided to ban evil things like Youtube Downloaders from their store as well, which is a far more impactful given their increased level of control 'for your safety.'
good one.
I am not sure why people view it as cynical to assume that for-profit corporations act out of self interest.
Have you ever gotten a company you worked for to authorize spending for something where you didn't justify it in terms of its benefit to the company? Was it millions of dollars like Google has spent on this HTTPS thing?
To assume that Google is not doing this for profit would be to assume that they are incompetent or derelict in their professional duties, and that seems unlikely to me in this case.
Yes, actually, and i was managing enough people that it was a dent (IE xx million a year investment in people alone). That company was, in fact, Google.
"Was it millions of dollars like Google has spent on this HTTPS thing?"
Yes.
"To assume that Google is not doing this for profit would be to assume that they are incompetent or derelict in their professional duties, and that seems unlikely to me in this case."
I'm going to disagree with you based on my experience above :)
Can you explain how you spent millions of dollars on something that had no benefit whatsoever for your company?
Now, you may have done something that had more ephemeral benefits and did not have directly attributable immediate revenue impacts, but I am pretty sure that it benefited your company somehow, and I am pretty sure that you justified the expense in terms of the benefit to your company.
If I am wrong I would be interested to hear the details of this.
In what sense? Like why they let me do it? Because they aren't as profit driven as you seem to believe. I'm sure parts are, but not the part i was in. Additionally, the founders and CEO definitely cared more about doing the right thing than trying to eek out another little bit of profit for something.
Unfortunately, it's not public in the particular case i'm referring to, so in that case, you'd just have to trust me.
I have also managed similarly not-profit driven things, that are public, like election information publication (which was also xx million worth of people). This data and work was explicitly kept away from any profit driven part of the company, and not driven, at any level, by a desire to profit (In this case, eric thought we should do it, as did sergey, and they very much wanted it to be done because it was the right thing to do, and didn't want us to care one whit about either the business or goodwill aspects) I'm sure you will contrive a motive. But you can contrive all you want, it's basically "your random thoughts" against "the people who actually funded and supported it", and i trust them at their words.
"Now, you may have done something that had more ephemeral benefits and did not have directly attributable immediate revenue impacts, but I am pretty sure that it benefited your company somehow, and I am pretty sure that you justified the expense in terms of the benefit to your company.""
You've moved from claiming, essentially, direct commercial benefit (solidification of monopoly position) to "any benefit at all". I'm pretty sure no matter how i answer you are going to try to contrive benefit out of it.
But i asked explicitly (when dealing with the non-public thing), and the answer all the way up to, as far as i know, Larry, was "no, we should do this because it's the right thing to do, we don't care if it benefits us".
I did not justify the expense in terms of benefit to my company.
As a lawyer, i can also tell you the professional duties you claim are either non-existent or not as absolute as you make them.
Google, and pretty much all corporations, are simply not the black and white things you paint them to be.
(and also, for the record, i actually very much hate corporatism :P)
"under American law we have a fiduciary responsibility to our shareholders to account for things properly, so if we were, for example, to just arbitrarily decide to pay a different tax rate than we were required to, a more favourable one for example to a particular country, how would we account for that?" - Eric Schmidt on why Google paid "£3.4m in tax on £3.2bn of sales" (.1%)
https://www.theguardian.com/technology/2013/may/27/google-er...
I'm really unsure what is this comment supposed to add to the discussion. It doesn't respond substantively to any point i made, it's not even relevant to the quote you are responding to, it's not caselaw or legal argumentation, it's a CEO giving a political answer to a question. Is that supposed to be shocking or something? I'm not even sure.
Truthfully, it makes it seem like you aren't even trying to have a real discussion, you just want to grind an axe.
[1] "While the duty to maximize shareholder value may be a useful shorthand for a corporate manager to think about how to act on a day to day basis, this is not legally required or enforceable ….
Under this legal regime, it is not malfeasance for boards or corporate chiefs to make decisions that do not maximize shareholder value."
[2] "Contrary to what many believe, U.S. corporate law does not impose any enforceable legal duty on corporate directors or executives of public corporations to maximize profits or share price" (https://corpgov.law.harvard.edu/2012/06/26/the-shareholder-v...)
[3] There are only two legal duties here. The duty of care and the duty of loyalty. As I said, neither is about maximization of profits, though you will occasionally find courts with loose language around the duty of loyalty. The duty of loyalty's history is about not making money at the corporations expense - you must put the corporation's interests above your own. Transforming that into a "you must maximize profit at all costs" is ... a pretty far step. Again, 99.99% court cases here, and traditional breach of this duty are about either taking a corporate opportunity for yourself or making self-interested transactions.
A direct quote of Google's long time former CEO making the exact same argument I am seems pretty on topic to me.
> Eric is legally wrong about this
Maybe, but Google became a $500B+ company with him thinking and acting this way, so being "wrong" pays well apparently.
It's only on topic because you keep changing topics! You've now gone and pretty much ignored every point made and just shifted discussion to something else in pretty much every reply. It's not even the same argument you have made in these replies, as you claim. (Eric is talking about accountability to shareholders, you started by talking about direct benefit to the business. These are incredibly different things)
So while this has been fun, it doesn't seem very useful or constructive.
When you can't counter on facts or logic attack the speaker and impugn their motives.
> You've now gone and pretty much ignored every point made and just shifted discussion to something else
When someone directly refutes you accuse them of trying to change the subject, which is what you are doing.
"Google and others like Mozilla have had to drag many site owners kicking and screaming" - I was dragged into this by the Google threats. Spent hours on it. Come to find our most popular few pages use a script that just will not function over https - no way to make it happen.
Then I spent hours crafting htaccess rules to make some pages https (home and password pages) - and some pages forced non-https (the 5 pages we have with needed chat script on them) - more hours into updating links on all pages and everything -
then come to find out the browsers have a function where if your home page is https only then it can't pull the sub pages as non-https (maybe it's the other way around, it's been a while) -
So I had to go and undo all the changes. I've been spending time trying to help develop newer chat scripts to have all the functionality of the old one our users prefer - and to no avail. So as google forces https use on sites to be in it's results, and now to not be labeled as insecure - we currently have to choose to remove our most popular functions on our site or lose the google battle completely.
We are still trying to get a newer chat system up and running that has our old familiar functions, but we don't have the resources that google and others have obviously.
We want https so bad, we love, love, love more encryption the better. It just has not been an easy thing for us to implement, and we've tried many things, included pushing our users to newer html5 based chat systems and such. Nothing has panned out quite yet. Fingers crossed we make strides in these areas before it gets worse.
Computer goes out of sync with some kind of cache server, welcome to HSTS errors and not able to surf to any site with cached content there.
Visit customers that have self signed certificates on their guest network, hello LTE to be able to do anything.
Yes, security has downsides, but in my opinion those downsides are well worth it for the benefits.
If a website puts out an HSTS header, they are telling the browser they need a higher bar of security than regular SSL.
Chrome: type badidea
Visit customers that try to MITM you, get protected. That is, in fact, the point.
Similarly: I have a static site (no tracking, no PIIs) that's currently hosted on a friend's VPS. HTTPS is out, because they're already using it for something else, and Apache can't know which vhost the user is requesting in time to present appropriate certificate. Maybe there's a workaround for that, but neither I nor my friend know of any, we've both already spent few hours looking, and I do not feel like spending even more time figuring out, or moving it to a dedicated VPS with its own IP.
Basically, on the one hand I'm all happy. On the other hand, I totally do not want to do the work.
And beyond that, all the extra complexity introduced everywhere that you mention, and that I also had happen to me.
Support is at about 97.9% globally: https://caniuse.com/#search=SNI - Effectively every browser released since 2010 plus IE 7 and 8 on Vista.
I find it disappointing that there are any sites that large that are using HTTP.
https://transparencyreport.google.com/https/top-sites
The last category features many Chinese sites. I could speculate about why that is, maybe the Great Firewall gives citizens no reason to bother trying to achieve security, maybe Chinese culture opposes privacy, maybe everybody in China is running Windows 95 still. But whatever the reason, that's an observable fact.
There's also a whole bunch of crappy British tabloid newspapers there. Given their print editions are specifically printed on the worst quality paper that will take print ink, and they are routinely accused of "gutter" journalism, perhaps it isn't a surprise that defending their reputations through the use of encryption isn't a priority? Or you know, maybe British culture... British great firewall... etcetera. No idea.