Reply to Consider Disabling HTTPS Auto Redirects by @tdarb

One thing this article misses is the fact that webpages are delivered over the Web to Web browsers.

The vast majority of browsers are application runtime environments. Serving pages to users’ browsers creates a software distribution platform. Serving pages in cleartext is a way to give permission to users’ ISPs, network administrators, and governments to serve their malware instead, under your name, whether or not your page includes any scripts of your own.

People can’t always choose their networks, service providers, or governments. They aren’t always equipped to deal with content injection and page alteration.

This isn’t a “fear-based tactic”. It’s an acknowledgement of our reality: networks are hostile. There are no robust measures to stop an intermediary from altering unencrypted traffic, yet there are strong incentives for all able parties to do so. That makes malware injection a perfectly reasonable concern. Moreover: multiple ISPs, including Comcast and Vodafone, have been caught injecting JavaScript apps into unencrypted pages. Governments are no stranger to content injection either.

If you want to serve in cleartext, pick a protocol that’s not part of an application delivery platform. Gopher is a popular option.

#POSSE note from https://seirdy.one/notes/2022/08/03/on-enforcing-https/

Folgen

@Seirdy @tdarb But wouldn't it be more helpful to teach people to disable javascript by default, as that would also help against so much spying that goes on with perfectly good https certificates? And then teach people to know the difference between http and https? That would help meaningful privacy a lot better than forcing https on everyone. See also blog.tfiu.de/foced-https-redir

Melde dich an, um an der Konversation teilzuhaben
troet.cafe  - Mastodon

Hallo im troet.cafe. Dies ist eine deutschsprachige Mastodon Instanz zum tröten, neue Leute kennenlernen, sich auszutauschen und Spass zu haben. +++ Bitte beachtet, dass derzeitig keine Neuregistrierungen mit gmail.com, hotmail.com, yahoo.com und outlook.com Adressen angenommen werden. +++ Wenn Ihr keine andere E-Mailadresse habt, lasst Euch bitte von jemanden den Ihr kennt einladen, oder aber schickt mir eine E-Mail mit der Bitte um eine Einladung. Ich schicke Euch einen Einladungslink zu.