[Clueless anti-s]ecurity quote of the week
[Clueless anti-s]ecurity quote of the week
Posted May 7, 2015 12:42 UTC (Thu) by szbalint (guest, #95343)In reply to: [Clueless anti-s]ecurity quote of the week by jschrod
Parent article: Security quote of the week
There is a disparity here aswell, it's your site, but our security is what's at issue here. Mozilla is nudging you to secure your site not because you need it, but because everyone who views your site needs it.
I don't think Weinstein disputes the need for https-everywhere, he just seems to take issue with the tone he seems to detect from Mozilla on how to go on about it.
(I think he's wrong on several points - Mozilla is not really agressive in pushing https, since they don't plan on disabling plain http anytime soon but rather only enable new features over https. He's also wrong about the tls certificate infrastructure and self-signed certs. It's not ideal, noone is saying it is, but it's both the practically best we've got and it's been (not even that slowly) getting better, we have both HSTS and HPKP, deprecating SHA-1 certs is well underway and CA baseline requirements are getting stricter over time, enforced by the threat of removal from the Mozilla/Chrome trust store. Let's encrypt will bring command-line-only free certs to the masses and there is Certificate Transparency to better audit who issues what kind of certs.)
