Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

This is just pointless scaremongering.

Remember what happened when msie added warnings for this a decade ago?

People got so fed up with "security"-warnings that they just clicked "OK! OK! Whatever. Get the fuck out of the way!". And they did it to ALL warnings, serious ones too.

Glad to see history repeat i itself.



I think it's fine they are doing it, but success will depend on how they go about it.

For example, they should probably start by changing only the link's icon to show it's insecure - as they propose, perhaps making it yellow instead of white. Then after a year more they could show that icon in red. After another year, they could give a light pop-up warning, and after a year more, they could put an aggressive malware-like (hey, it's not too far from the truth when NSA and GCHQ are firehosing and datamining all plain-text connections...) red pop-up warning that says the connection is insecure.

Then after a year more, they could even grey out or take out the "continue" button, and only provide a small link instead, so most people run away from that site.

I think 5 years (2020) is a reasonable time period to get to that point. If 7 years after the Snowden revelations we don't even have most of the Internet secured with HTTPS, then we really suck and deserve the totalitarian regimes coming at us (it won't be just the 5 Eyes doing mass spying in 2020).

Besides, it's not what the users think that matters, it's what the web developers do knowing that in 2 years their site will have an insecure red icon and in 3 years it will have a pop-up warning, and in 5 years users will essentially be driven away from their site. Even if 90 percent of the traffic keeps clicking through the warnings, can they live knowing their site shows that to the users? So this is a battle for convincing web developers, not users, that they should be securing their sites.


Agreed.

There are so many websites on the internet which do not gather sensitive data from the users but display read-only content.


If you had checked my web-browsing over the last week it wouldn't be very hard to make an argument that I should be in psych facility, based on the number of suicide related searches I did. In all cases it was purely static content, but in the wrong hands it could be a huge issue for me.

I am only posting it here to prove a point: even static content can reveal a lot.


I don't think SSL is all that great for protecting broad interests.

If you are going to ten different domains in the same span of time that all contain suicide content and someone is snooping your connection, they can correlate what you're doing from the server names (especially if one of the domains has the word 'suicide' in it), even without seeing the page content or path portions of your web requests.

For exclusive content sites, it's a dead giveaway. If someone went to my domain (byuu.org) in HTTPS, then it's pretty obvious that they were interested in emulation, regardless of the encryption. There's already tons of services out there categorizing domains on the internet.

SSL's primary benefit is for form submissions, not for static content pages.

For something like that, your best bet at the present time is a service like Tor. Which even that isn't really perfect.


It's a good point, but most people don't care about that or government surveillance. Any friction introduced by things they don't care about will be seen as annoyance and will be ignored at best. And since absolute majority of websites are likely to stay on http forever - warnings won't do much good and probably will get disabled again in the future.

The good news is: more sites will switch to https.


And it would be so much easier to make a murder look like a suicide with a (public) search history like that.


Reading certain articles reveals sensitive information about you, the reader, too.

Do you really want every node in the network to know that you like NSFW content or are heavily into my little pony?


Would https be better in that regard? (e.g. tracking of visited URIs by the network)


Yes, because the URI is also encrypted in HTTPS (although it can get leaked in other ways; see the discussion at http://stackoverflow.com/questions/499591/are-https-urls-enc...).


But the host is not, and many services exist to categorize the content of domains already. What is the statistical difference between innocuous-site-with-every-kind-of-content-ever.com/friendship-is-pornographic and mlp-fip.com? If more sites are like the latter, then HTTPS will only hide which MLP pictures you are looking at, and not that you are looking at MLP porn. And if a site like the former became too large, we'd have to worry about the government issuing secret trace/tap requests against them.


That thread misses the most important way: the length of the request and the length of the response. On most small sites, the combination of the two will be enough to uniquely identify what page you're visiting.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: