In the year 2023, an Egyptian politician had malware delivered to his phone via MITM when he visited a website that was not using HTTPS.

This is why we must finish encrypting the goddamn web.

@evacide Browsers should just flat out refuse to connect to anything that isn't a modern https version unless the user clicks through like five dialogue boxes and solves a riddle. The only exception should be made to local IP addresses (for router configuration and the like).

@brianstorms @Infoseepage @evacide

as two people whose friendship is based on intelligence, we should first determine what actually happened here, and then also consider whether shutting down the open web is worth the tradeoffs. was there another way to add "security" to the web without breaking so many sites. and why do you trust google not to be evil with the power you're willing to hand over to them.

nothing is so simple as the battle cry you see that started this thread.

@davew @brianstorms @Infoseepage @evacide HTTPS wouldn't completely solve the problem anyway. Egyptian company has already been caught with network devices using valid certs that redirect SSL traffic to sites they control (or just to MITM view the traffic). Google caught it with certificate pinning but no where near immediately.

@sayitintexan @davew @brianstorms @evacide At the very least it forces malicious actors to up their game and reduces the potential number of such people with the skills to carry out such attacks. This is a case where we shouldn't make perfect the enemy of the good.

Follow

@Infoseepage @sayitintexan @davew @brianstorms @evacide Are you suggesting that there are no tradeoffs whatsoever to enforcing an HTTPS requirement on every URL? The two options are only "perfect" and "unalloyed good?" Because that seems to be an underlying assumption with which I respectfully disagree.

@pwinn @sayitintexan @davew @brianstorms @evacide I'm not terribly interesting in having some big throw-down debate over the issue.

There is computational costs to establishing secure connections. We're currently wasting energy on the scale of medium sized nations to coin magic internet money. Maybe use some of that for security instead.

Maintaining certificate infrastructures is a pain.

@pwinn @sayitintexan @davew @brianstorms @evacide Users overwhelmingly don't have the intellectual capacity to consider "where does this link go and what are the consequences of me clicking on it." More advanced users reflexively do stuff they shouldn't.

We're currently in what seems to me to be an unusually large meltdown which is affecting institutions and individuals alike across the globe.

@pwinn @sayitintexan @davew @brianstorms @evacide
Http is a very obvious area of vulnerability and exploitation and IMO a good one to plug outright, because the dike is spouting a lot of water and we've only got so many fingers.

@pwinn @sayitintexan @davew @brianstorms @evacide Cleartext client <-> server communication imo needs to end. Clients need to know that the server they're talking to is what it claims to be and communication between the two needs to be free of surveillance. Saying these simple things are actually complex problems is a gross understatement and has been the work of generations.

Are the solutions we have perfect? No, but I think we need to be working towards a better default.

@davew Sorry to include you if it was not to your liking. Not sure which client you are using, but on my server at least there is an option accessible by clicking on the three horizontal dots to the right of the post that includes a Mute Conversation option. Not sure how well it works.

I'd love for there to be some "temporary mute" feature to mute someone for like a couple of hours if they're getting ranty about something about which I have no interest.

Sign in to participate in the conversation
CleverLibre Social

CleverLibre Social is an inclusive social instance for open discussion, learning, and community.
All cultures welcome.
Hate speech and harassment strictly forbidden.