Post B4IMTfPJmYuGGIatwO by SuperDicq@minidisc.tokyo
(DIR) More posts by SuperDicq@minidisc.tokyo
(DIR) Post #B4IM4NcYm5ovrIjKt6 by sigmasternchen@comfy.social
0 likes, 1 repeats
Today I read the argument that enforced HTTPS might actually be bad because it means you have to use a decently modern web browser. As someone who tried to use Windows Vista in 2026 I can certainly understand that. (And Vista is actually doable using Firefox ESR.)However, as a privacy fanatic I feel compelled to also point out that encryption is pretty much always good. And at the very least transit encryption should be the default for everything.What do you think?
(DIR) Post #B4IM4Noc3HSgSgMxfs by SuperDicq@minidisc.tokyo
0 likes, 1 repeats
@sigmasternchen@comfy.social Websites that serve static pages do absolutely not need HTTPS. What the hell are you going to spy on? You're going to man in the middle sniff my already publicly available information?HTTPS should only be a requirement for websites that handle private data.
(DIR) Post #B4IMTfPJmYuGGIatwO by SuperDicq@minidisc.tokyo
0 likes, 0 repeats
@aetios@sns.minovsky.space @sigmasternchen@comfy.social Don't pretend that isn't possible with HTTPS.
(DIR) Post #B4IMhJ3FhJvyyqmE08 by apropos@fsebugoutzone.org
0 likes, 0 repeats
@SuperDicq @sigmasternchen HTTPS is reliably MITM'd in the datacenter. The primary actual purpose of web encryption today is probably just to make people think that this is a solved problem and that there's no need to learn how to use asymmetric encryption.
(DIR) Post #B4IMhJCp7jafSXFrv6 by SuperDicq@minidisc.tokyo
0 likes, 0 repeats
@apropos@fsebugoutzone.org @sigmasternchen@comfy.social It definitely reduces attack vectors in transit though. It's not a pointless technology. But I think using it on websites that do not handle private data is a little overkill.
(DIR) Post #B4IN7EIjyuAtmFNmka by rozenglass@fedi.dreamscape.link
0 likes, 0 repeats
@sigmasternchen@comfy.social @SuperDicq@minidisc.tokyo Knowing the public information does not make it less interesting to know what specific information a specific person is interested in. Especially in high-stake political situations. Visited website X.lol, is not as damning as visited 200 pages of the form X.lol/something-that-can-get-you-hanged. And on lower stakes, not having TLS encryption means your ISP (and any listener in the middle, like your company or hospital or school, etc.) can build a psychological profile about you just from watching what you read. And worst of all, they can inject changes into the pages you read without you knowing, from injecting ads, to changing the content to what fits them; TLS also validates that the page was not tampered with by your carrier.I still don't think that forced TLS server-side is a good idea, except for things like login pages, or if you know that the content of your site can get people in trouble if casually inspected by their ISP. I think most of the internet should allow plain text connections if the client wanted that. I do think that web clients for the general public should by default enforce TLS, and only allow removing that by the user's explicit request.
(DIR) Post #B4IN7EWZ9VEYT7qpIe by SuperDicq@minidisc.tokyo
0 likes, 0 repeats
@rozenglass@fedi.dreamscape.link @sigmasternchen@comfy.social Oh right I forgot that most people on the internet only visit like 5 websites that have literally everything on them. In my mind the internet is just a bunch of websites with a small amount of pages still where you can assume someone has seen the whole website if they visited a website in the first place.
(DIR) Post #B4INN35XRFVVdNkarw by SuperDicq@minidisc.tokyo
0 likes, 0 repeats
@rozenglass@fedi.dreamscape.link @sigmasternchen@comfy.social But I do think we are shifting goalposts slightly.Should websites block unencrypted traffic if they user really wants to disable it? If the user is aware of the issues, why shouldn't they be able to retrieve public information without HTTPS, because they are for example using an outdated operating system?Is the risk high enough that this traffic should be blocked and the website should be completely inaccessible for these users?
(DIR) Post #B4INPWuBYDviglchYO by SuperDicq@minidisc.tokyo
0 likes, 0 repeats
@aetios@sns.minovsky.space @sigmasternchen@comfy.social It's not always available. You could be using outdated software like the OP mentioned.
(DIR) Post #B4INUlmdf40EHTalPc by SuperDicq@minidisc.tokyo
0 likes, 0 repeats
@aetios@sns.minovsky.space @sigmasternchen@comfy.social Getting the information without HTTPS is probably better than not being able to retrieve the information at all, unless it is private.
(DIR) Post #B4JZv64WFGmxLEEfFg by rozenglass@fedi.dreamscape.link
0 likes, 0 repeats
@sigmasternchen@comfy.social @SuperDicq@minidisc.tokyo I think it's probably a good thing that big sites like Facebook or Twitter or such refuse plain text, because if they didn't, "oppressors" may force their populace to only use plain text browsers so they can spy on them, and the oppressed won't do much about it because they don't understand the implications. While the current status-quo makes forcing the use of plain text clients equivalent to blocking all major internet services, which would be more revolting to the populace. Big corpos probably know that, and force TLS as an intentional measure against allowing "enemies" to spy on users, and leave the control in big corpo's hands to give the spying data only to "friends". The use of Cloudflare by half the internet perhaps demonstrates that it is not about privacy, as much as "we only allow the eyes we want to allow".As for smaller internet sites, personal sites, blogs, or archives of scientific knowledge and such, I'm very much in favor of them accepting plain text connections if the user requested explicitly. Perhaps, a middle ground, to work around the stupid behavior of modern web clients, would be to force TLS on the main site, but then have a mirror of the entire site on a subdomain (notls.mysite.org) that does not force TLS connections. This can even go for big corpo silos, if they wanted, e.g. notls.facebook.com, but then again they probably won't do that, because they would risk losing the monopoly power they hold over that information.
(DIR) Post #B4JZv6hrsyGRJGe5aK by sigmasternchen@comfy.social
0 likes, 0 repeats
@rozenglass@fedi.dreamscape.link @SuperDicq@minidisc.tokyo I kinda like the suggestion actually. And depending on how the site is hosted having a non-TLS "mirror" would be super easy to set up.
(DIR) Post #B4JZv79AFU6AfvPt8C by SuperDicq@minidisc.tokyo
0 likes, 0 repeats
@sigmasternchen@comfy.social @rozenglass@fedi.dreamscape.link For me it's literally impossible to set this up because I am stupid and I bought a .dev domain years ago and this TLD requires TLS
(DIR) Post #B4KZMfzYtjAHlgSoTI by rozenglass@fedi.dreamscape.link
0 likes, 0 repeats
@sigmasternchen@comfy.social @SuperDicq@minidisc.tokyo I didn't know entire TLDs required TLS before. Apparently, buy having them in browsers' "HSTS Preloading Lists". This is disgusting. And .dev at that, which sounds like a domain you might use for a development environment. But anyway, since clients themselves ship the HSTS lists, that means if you provide plain HTTP it can still be useful to clients that don't use those HSTS preloading lists, and I assume any HTTP-only client will not have such lists. If the goal is more compatibility, then that should still satisfy. Of course clients that use HSTS preloading lists will only connect using TLS. If you want such clients to be able to connect to your mirror without TLS, then getting a secondary domain for the mirror would work, if you so wish.
(DIR) Post #B4KZMgES0N4gVrQhg8 by SuperDicq@minidisc.tokyo
0 likes, 0 repeats
@rozenglass@fedi.dreamscape.link @sigmasternchen@comfy.social Yes, but I don't to pay for a second domain. I should've checked what "HSTS Preloaded List" meant before I bought the domain. It's fine though, I don't mind having to use TLS, it's not a big deal.