Reddit co-founder: Tech companies can help fight NSA snooping [video]
rawstory.com
rawstory.com
The bottom line is regular people don't know the difference between entering "www.mybank.com" or "https://www.mybank.com", they never do the latter, and they rarely notice if a page is non-HTTPS if it has other icons that make it seem secure (e.g. "McAfee protected")--hence the reason sslstrip exists in the first place.
# curl -i reddit.com/login
HTTP/1.1 302 Moved Temporarily
Server: AkamaiGHost
Content-Length: 0
Location: http://www.reddit.com/login
Date: Sun, 30 Jun 2013 22:50:13 GMT
Connection: keep-alive
# curl -i www.reddit.com/login
HTTP/1.1 302 Moved Temporarily
Content-Length: 0
Location: https://ssl.reddit.com/login
Cache-Control: no-cache
Date: Sun, 30 Jun 2013 22:50:24 GMT
Connection: keep-aliveAlso, I'm not sure that there is a business model fix for this. Presumably if someone from the government shows up and insists that certain equipment be installed at your company then you have no legal powers to resist that. If there are data retention laws then you have to store data for some amount of time.
Technology can go some way towards ameliorating the problems, but I think the ultimate fix for this bug is at the political level.