History of the browser user-agent string (2008)
webaim.org
webaim.org
Even more important is to stop leaking your private IPs: https://browserleaks.com/webrtc
Even more important: Stop using http by default when users enter a hostname into their urlbar. https is a joke at the moment. Because when users go to somecoolsite.com they are at first connecting via http. Now a man in the middle could just proxy their connection. No security at all.
First of all its additional complexity that has to be implemented by the website. More work, more things that can go wrong.
Second, it needs to store data on users machine. It is basically a cookie. So users would need to kiss goodbye privacy to "benefit" from it.
Third, it only works if the user has connected to the site on the same browser before. And did not delete the cached HSTS data.
So in sum, it kills privacy, works only sometimes and piles up on the stack. It's a typical bandaid solultion. Instead of fixing the root cause, it makes things worse.
The users machine cannot be part of a legitimate threat model. Either it’s compromised or it’s not. Either it’s FDE’d or it’s not. I wouldn’t even pretend that a HSTS assertion here or there would even make a difference in the shitshow that is browser cache.
I agree it’s a hack, but at this point I pretty much think that about crypto standards, period. Having HSTS is better than not, and we’re a while away from disabling unencrypted comms.
As for user agents. Nope. We connect those directly to better user support outcomes, especially for our less technical users. Abandoning that would be a foolish conceit.
[0] https://addons.mozilla.org/en-US/firefox/addon/smart-https-r...
The move would likely have to be coordinated among the browser vendors, but it wouldn't surprise me if Apple decides to lead the charge on this one. All iPhones being https by default would put a massive demand on crappy systems that assume they can mitm users.
0: http://www.chromium.org/Home/chromium-security/marking-http-...
(I know I sniff for iPhone but that’s about it)
I've seen comments from Youtube devs that say progressive enhancement is too slow, so they use the useragent to choose what bundle to send.
I get it, sometimes sniffing is necessary for some things. But it's embarrassing to see a company of Google's size and caliber so reliant on it, and to see their developers so quickly accept that they're just going to abandon what is one of the cornerstones of good web development.
2013: https://news.ycombinator.com/item?id=6674812
Discussed at the time, though not much: https://news.ycombinator.com/item?id=298844