Ask HN: Why doesn't HN use SSL/HTTPS for its login form?
Sorry in advance if this has been covered before-- I did a quick search and didn't see any recent posts...
Sorry in advance if this has been covered before-- I did a quick search and didn't see any recent posts...
1)HN is a side project for a busy man, and SSL/HTTPS simply isn't very high on the feature list.
2) Arc, the language HN is written in, doesn't support SSL/HTTPS
I'll do it with this comment, too.
I'd be happy to test and supply an nginx 0.8 configuration if that would help.
While that is the case for most sites, HN doesn't require you to enter your current password when changing your password (or any other information for that matter).
So in the old days, that was networks using hubs (instead of switches), these days it's wireless networks.
Just keep it under your hat lest someone put it into a firefox extension.
> It's a social news site low risk target for that sort of thing.
See also: Gawker.A different attack, yes, but they're targets too.
http://www.imperialviolet.org/2010/06/25/overclocking-ssl.ht...
"If you stop reading now you only need to remember one thing: SSL/TLS is not computationally expensive any more."
Will someone please explain to me in succinct terms what the purpose for having a super-secure login would be -- that is, what the threat and how SSL will protect against it??
Even you, who only log in to post snarky comments, have posted links to your personal blog and projects.
That said, as (mostly) technical people here at HN, we should realize that putting our machines in a position where traffic could be sniffed or altered--that is, on the same public WiFi or subnet as a malicious user--is risky to begin with. DNS and ARP poisoning could redirect any HTTP requests to anywhere else on the Internet whether or not it's trying to initiate an encrypted connection. SSL is an important aspect of security, but can't be relied upon to protect you in a hostile environment.
In the very unlikely event that my HN password gets sniffed, I'll need to change my username or ask for a password reset. Worst case is someone posts a few derogatory comments under my name. I'll survive! The same password is used on a few other sites where the loss to me would be about the same: not a big deal.
I just don't buy that lacking some form of security dooms you to whatever penalties the security may have protected against, if indeed any.
Yes. Criminals are oddly enough generally pretty good at cost-benefit analysis. At least in the short term.
I still feel wronged (it's a little annoying) but I still don't lock my doors (the amortized cost seems to be about $15/year where I tend to park. It's 99% about the time/money trade-off and 1% about what's morally right.
I know people sometimes try too hard to justify PG's actions. But, PG is a big believer in making products and services extremely simple for the users. It is surprising that he would expect users to be careful enough to not use their primary passwords on HN. The only excuse that I can believe is that he simply doesn't have time for it.
I can't imagine why anyone would break into HN, but if it actually happened, who would be to blame?
Update: Corrected Typo
Arc missing SSL support, HN is a side project, pg-pg-pg-is-a-busy-man, CPU usage, $$... WTF!? You better do it right, or don't do it at all.
When months ago I registered, I used a "serious" password. Then, curious, I took a look at the page source... aargh, no SSL!
Immediately I changed my password with an "offensive" one. And I invite everyone to do the same. Hey pg, hey sniffers, you can read my password, don't you? Go, go, go to read my password!
And as usual, pg fanboys, please be rapid downvoting me.
State of the art and best practices FTW!!!