Self-hosting a static site with OpenBSD, httpd, and relayd
citizen428.net
citizen428.net
Somewhere in history we took the wrong turn making a simple thing like publishing a website that complicated.
Why is all this configuring with different headers necessary to publish a web site? For me it looks like the system is broken.
Aside, I was not complaining about the Let's Encrypt stuff, I'm totally ok with using https nowadays.
For me HTTPS is there to protect the user, not the server. If you want to protect the server minimize the surface of attack, use very strong passwords, and serious resources ownership (chown) setup.
If someone can hijack the DNS of a client, they can send the client to a totally different copy of the static site. The client will have no idea and the site could contain malicious code or information. With a certificate they will get an error saying this is not the correct site.
That assumes there has been no CA tampering or that they haven't managed to hijack the DNS of lets encrypt either.
But how to trust our browsers?
For example in Firefox there are as CAs:
- Xramp security services, but it looks like their web site is not reachable [1] A related website [0] is even not on HTTPS? How this is supposed to be a valid CA?
Yet if a certificate is signed by this CA, a browser will signal no warning (except if it tries to reach their OCSP end point).
[0] http://xramp.com
[1] www.xrampsecurity.com
It's building a chain of trust. If any link in that chain is compromised then you have a security hole.
It's not perfect, much like locking your house only goes so far when someone can cut a hole in your wall and walk in.
https://www.zdnet.com/article/google-catches-french-govt-spo...
Such a attack would immediately end up with the relevant CA being removed from the certificate stores across popular browsers/OS, quite detrimental to the business who owns them.
This does not mean that HTTPS doesn't provide security, compared to plain-text, it is a significantly harder to game it, verging on the edge of infeasible.
Absolutely, but when I look at the list of CAs (~70) that are preloaded in browsers:
* Most of them are unknown to most people => How to know if there is no malevolent CAs?
* A relevant number are from countries that are not so free. => What power has a SME like Firefox against let's say Turkey, Hungary or China states?
The organisation behind Firefox is the Mozilla Corporation, which is owned by the Mozilla Foundation. It's not particularly easy to find out what its legal status is, but that probably doesn't matter. It is not obliged to carry anyone's root certificates. There would be a market share cost for not doing so, but that's it.
CT logs make issuance of certificates very public, that allows the community to react to mis-issued certificates very quickly, this however doesn't stop a CA from just not submitting the cert to CT logs.
Browsers like Google Chrome check the certificate in CT logs, and would refuse to work otherwise.