I am getting fed up with Google trying to steer how the web should be. Already changed to Firefox.
Also when I think about this, this only hurts legacy windows applications which probably is hosted on a non-http site. I dont like this move at all.
I am getting fed up with Google trying to steer how the web should be. Already changed to Firefox.
Also when I think about this, this only hurts legacy windows applications which probably is hosted on a non-http site. I dont like this move at all.
TLDR: In this approach, http:// sites can link http:// executables, but https:// sites cannot.
Mixed-content rules would block even loading http:// images on a https:// page, so wouldn't you think that blocking .exe downloads from http:// sources on an https:// location would also be blocked?
I don't love Google, but this doesn't seem like a bad idea.
There are workarounds for this (using a redirector service and unique hostnames) but that is an additional request of donors who are providing them a lot of bandwidth for free.
It’s not a great reason, but it is a reason.
I second this. Their market share affords them far too much luxury with not nearly enough impartial oversight.
> I dont understand why they are doing this.
I do understand why they're doing this. Me and you are smart enough to know to only trust a download from a secure connection. Others don't. I've fixed two computers THIS MONTH from people who opened email attachments and then proceeded to click past all of the Office security warnings. Both of them were Kovter droppers. The average user doesn't know what the padlock means, and if you hid a non secure download behind an https redirect they wouldn't even know.
Another story, just last week, my town of 9k people has a "social network" based on dotNetNuke on some sketchy shared/co-hosted server without HTTPS. They tried to spam their network on a local FB group recently and they don't even have an SSL cert. Still, the sheer volume of idiots who visited and posted comments like "there's a bug, I can't create an account" or "just signed up!" was disgusting. I posted a stark warning and chewed out the spammer for not taking the 10 minutes to get a free SSL cert, which was when I learned of their sketchy hosting situation.
So you see, not only do regular users not know what their looking at on the internet; other web developers also have no idea and don't really care. They insisted to me they have their own security measures which negate the liablity of not encrypting traffic; to which I responded that I could setup a fake AP at the local coffee shop and start stealing passwords if he didn't beleive me. The post was deleted after that, but most of the country bumpkins in my town stood BEHIND HIM!!! They thought I was being mean to a local business.
The boogey-man can't sneak up on us, but many people are just going through life and need someone to watch their back digitally. Besides, the only time you initiate a non-secure download of an application from a secure connection is when you've injected payload fetching code into an XSS vulnerability. I can see literally no other use-case unless the developer is an idiot (see paragraph 3).
Affording someone the ability to save face is among the reasons to consider making a private approach. And when irritated, slighted or indignant, when amped up somehow, not disengaging to cool down is the sort of thing I tend to regret.
It's a tall order to expect people to interpret an offer to steal passwords in a coffee shop to assert their need of your acumen as a beneficent act.
Here is a reply from Mozilla representative in that very thread:
"I would be very happy to push in this direction, limited by the amount of breakage and user-pushback we can expect."
http://lists.w3.org/Archives/Public/public-webappsec/2019Apr...
I don't know any normal user who would think twice about clicking "Yes" on a prompt like that when they're trying to install a program they just downloaded. There are plenty of legitimate programs that don't have a signature, and plenty of malicious programs that do.
https://docs.microsoft.com/en-us/windows-hardware/drivers/da...
Here's hoping that something like LetsEncrypt comes along for code signing or EV certificates, or that Microsoft makes the process easier somehow.
That's for EV certificates. Regular certificates are a lot more affordable: https://comodosslstore.com/ca/code-signing (~$100/yr). For comparison, apple developer program is also around $100/yr. Certum also provides discounted certificates for open source projects (around $30).
>Here's hoping that something like LetsEncrypt comes along for code signing or EV certificates, or that Microsoft makes the process easier somehow.
The only reason that letsencrypt can be free is that domains can be validated at 0 marginal cost. Code signing certificates are issued to persons or corporations, not domains. Because of that, the issuer has to do a bunch of manual checks that drives up the marginal cost of each certificate.
Also, letsencrypt has many corporate sponsors who directly benefit from https adoption. Who benefits from microsoft code signing certificate adoption? Only microsoft.
The Certum ones turn out to be about 135 Euro, after the mandatory super expensive (and super slow) postage for the key fob to store the key on is included.
They do have "Cloud hosted" ones available too, which don't need the electronic fob. But I don't know anyone who'd trust their electronic signing keys to "the cloud". ;)
I heard that you could use any smartcard/hsm, not just their fob, so there might be same savings there.
>They do have "Cloud hosted" ones available too, which don't need the electronic fob. But I don't know anyone who'd trust their electronic signing keys to "the cloud". ;)
What's the issue here? Certum is the CA so they can already issue whatever certificates they want. They don't need to steal your cloud keys. The only real threat is if their service gets hacked, but at that point the hacker could also re-issue your certificate with his keys.
There are plenty of examples of stuff that should be secure, being leaked.
Also, if Certum "gets hacked" that's not a generic blanket giving complete access to every one of their systems. It's entirely possible they could get "hacked" and the hackers would only obtain read only access to stuff, without penetrating whatever signing systems there are.
Using a local fob circumvents several of those particular threats.
The weirdly expensive and slow postage option makes me curious about other things though. But that's probably just my paranoia revealing itself. ;)
Do note that even then, there have been demonstrated exploits of package managers downloading over http, where the parsers were demonstrated to be compromised.
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-3462
(nice summary of the above CVE https://www.securityweek.com/code-execution-vulnerability-im...)
They want people to fear the desktop since they have no control over it nor way to monetize it and move them to the web where the only way to monetize software is through ads and subscriptions and they provide solutions for both (as well as the hosting/infrastructure for implementing those applications).