TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Increasing HTTPS Adoption

140 pointsby inianalmost 4 years ago

15 comments

flowerladalmost 4 years ago
What is sorely lacking today is an encryption solution for the intranet. When you are transferring confidential data (such as salary info) over the network in intranet situation we need to encrypt the information to prevent casual snooping using tools such as Wireshark. We don&#x27;t need to verify the identity of the server because that&#x27;s typically not a problem on the intranet.<p>Self-signed certificates used to be the solution in this situation. But browser makers have made it significantly harder, if not impossible to use self-signed certificates, by not allowing the user to visit sites that have self-signed certificates.<p>We need a simple solution for this -- a solution that works even for small businesses that do not have an IT department. (That means installing certificates on each end-user&#x27;s machine is not a reasonable solution.)
评论 #27836838 未加载
评论 #27839024 未加载
评论 #27837449 未加载
评论 #27836855 未加载
评论 #27836934 未加载
评论 #27837509 未加载
评论 #27838054 未加载
评论 #27839277 未加载
评论 #27837139 未加载
评论 #27836775 未加载
评论 #27838986 未加载
评论 #27837758 未加载
评论 #27841750 未加载
评论 #27836841 未加载
评论 #27839389 未加载
评论 #27839899 未加载
评论 #27841086 未加载
评论 #27838733 未加载
评论 #27837672 未加载
评论 #27838802 未加载
评论 #27839323 未加载
评论 #27842881 未加载
评论 #27837823 未加载
评论 #27839966 未加载
评论 #27839184 未加载
yoursunnyalmost 4 years ago
I hope HTTPS-First mode would become the default, so that the full page warning can finally convince my classmate to adopt HTTPS on their website that &quot;does not contain any private info so it doesn&#x27;t need encryption&quot;.
评论 #27837549 未加载
评论 #27837591 未加载
评论 #27841898 未加载
mgarciaisaiaalmost 4 years ago
&gt; In particular, our research indicates that users often associate this icon with a site being trustworthy, when in fact it&#x27;s only the connection that&#x27;s secure.<p>I had the idea that browsers were showing a grayed-down padlock for standard HTTPS certificates (ie, &quot;connection is encrypted&quot;) vs a full-blown green icon with the company name next to it for the HTTPS certificates that also validate identity (DV? EV? I don&#x27;t recall the meanings and acronyms).<p>I guess that&#x27;s where we should go now: make HTTPs the default (thus showing a standard icon that doesn&#x27;t call for any attention), a big red ugly icon alerting non-encrypted connections, and a green one with identity attached meaning you can indeed trust this particular site to really be your bank.
评论 #27837556 未加载
评论 #27837028 未加载
评论 #27837588 未加载
评论 #27839198 未加载
beefmanalmost 4 years ago
I don&#x27;t understand the holy war against http. Let those who want https use it. Forcing the additional friction of certificates on every site and use case is dumb.<p>Not even touching on the fundamentally flawed trust model behind https, here&#x27;s a sample of recent stories about expired certificates:<p><a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=25132182" rel="nofollow">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=25132182</a><p><a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=24237400" rel="nofollow">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=24237400</a><p><a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=24187920" rel="nofollow">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=24187920</a><p><a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=22227266" rel="nofollow">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=22227266</a><p><a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=18649932" rel="nofollow">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=18649932</a><p><a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=16541235" rel="nofollow">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=16541235</a>
评论 #27840894 未加载
评论 #27839735 未加载
corentin88almost 4 years ago
Removing the lock icon is a very good idea. I’m not surprised that Chrome’s team found out that only 11% of participants to a survey understood what it really means.
评论 #27840890 未加载
评论 #27837319 未加载
jasonkesteralmost 4 years ago
Can anybody suggest what might be the motivation for this? Beyond the silly &quot;bad people might tamper with the cat picture you&#x27;re shown&quot; one that is always given? Chrome hates http with such a passion that there must be some evil motive behind it that I&#x27;m not seeing.<p>Because they just keep making life more difficult for websites that don&#x27;t need SSL.<p>So now in addition to seeing a scary icon on the url bar with a scary message, my users are going to have to click past an interstitial banner just so they can visit a website and read silly travel stories. Chromium will try their best to convince them to leave, lest some nefarious agency on their home wifi substitute alternate silly travel stories that somehow cause them harm. In the 20 years the site has been live, I skeptical that this has happened often enough that we need to get Google involved.<p>It&#x27;s frustrating.
评论 #27838044 未加载
评论 #27839115 未加载
评论 #27838804 未加载
评论 #27840697 未加载
评论 #27838783 未加载
评论 #27841723 未加载
评论 #27840918 未加载
评论 #27840956 未加载
pupppetalmost 4 years ago
&gt; In particular, our research indicates that users often associate this icon with a site being trustworthy, when in fact it&#x27;s only the connection that&#x27;s secure.<p>Never really thought about that, but I guess it&#x27;s pretty obvious. I can totally see my folks downloading&#x2F;buying god-knows-what from a site because they see that lock icon.
评论 #27836995 未加载
tyingqalmost 4 years ago
No mention of ECH (Encrypted Client Hello).<p>Current status: <a href="https:&#x2F;&#x2F;www.chromestatus.com&#x2F;feature&#x2F;6196703843581952" rel="nofollow">https:&#x2F;&#x2F;www.chromestatus.com&#x2F;feature&#x2F;6196703843581952</a>
评论 #27840312 未加载
评论 #27840011 未加载
litoEalmost 4 years ago
My home network includes a router and several WiFi access points. They are managed through a browser, which means they have a built-in web server. I have them configured so they are only visible from the internal IP addresses and changed usernames and passwords from the built-in defaults, but there&#x27;s no way to install a certificate in them, let alone force them to use https. So whenever I use Chrome to reconfigure one of these devices I get warnings of impending doom. A big PITA.
jeffbeealmost 4 years ago
Interesting that &quot;Linux&quot; is the platform with the lowest observed adoption of HTTPS ... implies some kind of bias in the way Linux users use Chrome. ChromeOS, which is also Linux but I assume not included in the data with the Linux label, has by far the highest fraction of HTTPS.
评论 #27839780 未加载
WalterGRalmost 4 years ago
Has anyone found scheduling information about this? When can we expect this in Chrome, for example?<p>Edit: Oh, here we go: <a href="https:&#x2F;&#x2F;chromiumdash.appspot.com&#x2F;schedule" rel="nofollow">https:&#x2F;&#x2F;chromiumdash.appspot.com&#x2F;schedule</a><p>This is for Chromium and not Chrome, though:<p>...<p>Feature Freeze Thu, Jul 29, 2021<p>...<p>Stable Cut * Tue, Sep 14, 2021<p>Stable Release Tue, Sep 21, 2021<p>...
bullenalmost 4 years ago
HTTPS is not secure if someone has a root cert and wastes energy, if you need encryption you should roll your own.<p>I used <a href="https:&#x2F;&#x2F;datatracker.ietf.org&#x2F;doc&#x2F;html&#x2F;rfc2289" rel="nofollow">https:&#x2F;&#x2F;datatracker.ietf.org&#x2F;doc&#x2F;html&#x2F;rfc2289</a> for login which is simpler and uses less energy than public&#x2F;private key encryption and quantum safe out of the box.<p>Google of course has a root cert and is making sure less people can make web sites by building more protocol extensions that the average joe can afford to keep up with.<p>I expect to be severly down voted but it&#x27;s ok, I&#x27;m used to it by this point. Truth is always downvoted by vested interests to higher degree than average joes are willing to upvote it.
评论 #27841976 未加载
foobarbazetcalmost 4 years ago
I know it&#x27;s just another test, but the constant changes to the lock icon&#x2F;indicators that a connection is secure are becoming annoying...
BrandoElFollitoalmost 4 years ago
HTTPS is complicated.<p>python -m http.server → you have a web server that you can use for ad-hoc needs.<p>Coding TLS into a web framework is hard. Ah, I should use a proxy? So installing a TLS on a proxy is hard. Ah, I should use caddy with LE? Sure (I use it for years), now how do I do that for 10.2.3.10?<p>I understand why HTTPS is useful (to encrypt your traffic, certainly not &quot;to know you are on the right server&quot;), but it is a failure form the start - usability-wise.
gerdesjalmost 4 years ago
The &quot;hit piss&quot; (https) first thing is all very well but there are times when &quot;hit pip&quot; (http) is fine. You don&#x27;t generally use an Enigma machine at home.<p>We generally live in a RFC1918 n stuff world which describes &quot;internal&quot; and &quot;external&quot;. IPv6 focusses the boundary between you and me in a different way.<p>Why should my browser decide what I do on my own home network?<p>Why should a mere tool pontificate about stuff that I know more about than the kids who developed it? Fine, I should probably develop my own browser in ASM but I don&#x27;t speak nonsense. I sort of know what a processor register is but it would probably bully me.<p>I am increasingly seeing top down decisions from monstrously huge corporations &quot;for my own good&quot; and I am increasingly getting worried. I rant at my elected government officials because that is what they are for (I don&#x27;t really) but commercial corps are increasingly insinuating themselves into important discussions and their moral stance is undecipherable.
评论 #27840727 未加载
评论 #27844205 未加载