Slashdot Mirror


With HTTPS Everywhere, Is Firefox Now the Most Secure Mobile Browser?

Peter Eckersley writes "Over at EFF, we just released a version of our HTTPS Everywhere extension for Firefox for Android. HTTPS Everywhere upgrades your insecure web requests to HTTPS on many thousands of sites, and this means that Firefox on Android with HTTPS Everywhere is now by far the most secure browser against dragnet surveillance attacks like those performed by the NSA, GCHQ, and other intelligence agencies. Android users should install the Firefox app and then add HTTPS Everywhere to it. iPhone and iPad users will unfortunately have to switch to Android to get this level of security because Apple has locked Mozilla Firefox out of their platforms."

279 comments

  1. Breaks some websites by Anonymous Coward · · Score: 1

    Mixed-mode, beware!

    1. Re:Breaks some websites by stillpixel · · Score: 1

      Sorry.. I have a Mac. Does the EFF have any comments about that? lol..

    2. Re:Breaks some websites by stillpixel · · Score: 1

      You're not from around here are you? Next time try typing all of your text as one big block, it's okay.. we can grep it.

    3. Re:Breaks some websites by stillpixel · · Score: 1

      Hey man, like some new shit has come to light man.

    4. Re:Breaks some websites by Anonymous Coward · · Score: 3, Funny

      Sorry.. I have a Mac. Does the EFF have any comments about that? lol..

      Get a new computer. Stop being a hipster and run OpenBSD.

    5. Re:Breaks some websites by vomitology · · Score: 1, Funny

      C-C-C-COMBO BREAKER!

      --
      ~Knowledge is knowing that a tomato is a fruit, but Wisdom is knowing not to put it in a fruit salad.
    6. Re:Breaks some websites by Anonymous Coward · · Score: 0

      Considering the fact that HTTP Everywhere doesn't actually do anything I think you mean, some websites are already broken.

    7. Re:Breaks some websites by stillpixel · · Score: 1

      Sorry can't be a hipster.. too damn old. I've been a Mac guy since errr.. like 20 years ago now.

    8. Re:Breaks some websites by Anonymous Coward · · Score: 0

      Stop being a bigot. Mac is already a BSD.

    9. Re:Breaks some websites by stillpixel · · Score: 1

      Does it help that I use vi for coding sites? Does that satisfy you?

    10. Re:Breaks some websites by stillpixel · · Score: 0

      Of all the sites to comment spam you chose /. You know if this site is known for bringing down other sites without even trying to do so?

    11. Re:Breaks some websites by camperdave · · Score: 4, Funny

      Hey allaunjsilverfox2. Some kind of malware has infected your PC and is spamming Slashdot over, and over again. Perhaps you should use a malware cleaner to clean it up. Might I recommend AVG or Spybot?

      --
      When our name is on the back of your car, we're behind you all the way!
    12. Re:Breaks some websites by stillpixel · · Score: 2

      You know, I'm surprised you didn't recommend MyUnCleanPC, available at MyUnCleanPC.com It's awesome at infecting your computer and removing all that pesky real anti-virus and malware removal software that was slowing your PC down.

    13. Re:Breaks some websites by camperdave · · Score: 0

      Breaks some websites

      The recent enforced java updates have already done that. I have printers that I can no longer reach the embedded web interface on.

      --
      When our name is on the back of your car, we're behind you all the way!
    14. Re:Breaks some websites by stillpixel · · Score: 1

      i got nothing here.

    15. Re:Breaks some websites by stillpixel · · Score: 2

      I'm sitting here staring at my Macbook Pro and crying... because I will never see the joys of using MyCleanPC... I am at a loss. Where have I gone wrong... whoa is me.

    16. Re:Breaks some websites by stillpixel · · Score: 1

      http://theoatmeal.com/comics/o...

      seriously... it's life altering

    17. Re:Breaks some websites by lister+king+of+smeg · · Score: 5, Funny

      Sorry can't be a hipster.. too damn old. I've been a Mac guy since errr.. like 20 years ago now.

      The hipster movement is traced back to the 1940... you know back before it was popular.

      --
      ---Saying gnome 3 is better than windows 8 not so much a compliment as it is damning with light praise.
    18. Re:Breaks some websites by stillpixel · · Score: 1

      you deserve so much sir.. but my pockets are void of mod points.

    19. Re:Breaks some websites by Anonymous Coward · · Score: 0

      Does it help that I use vi for coding sites? Does that satisfy you?

      You should stop talking now.

    20. Re:Breaks some websites by Anonymous Coward · · Score: 0

      Fuck Apple and fuck the police.

    21. Re:Breaks some websites by stillpixel · · Score: 1

      Sorry.. it's late and I had a caffeinated beverage.

    22. Re:Breaks some websites by stillpixel · · Score: 0

      Try "Fuck and fuck the GOP/Tea Party" and I think you'd have a much better comment there.

    23. Re:Breaks some websites by narcc · · Score: 3, Funny

      AVG or Spybot? That's crazy. They pale in comparison to the obviously superior MyCleanPC!

      Why do you think he takes every opportunity to spread the good news?

    24. Re:Breaks some websites by black3d · · Score: 1

      But can it clean my HOSTS file?

      --
      "The true measure of a person is how they act when they know they won't get caught." - DSRilk
    25. Re: Breaks some websites by Anonymous Coward · · Score: 0

      It's not fucking funny. -1 isn't harsh enough punishment for that spam.

      Eeeeahhh BOB SAGET! FUCK!

    26. Re:Breaks some websites by Anonymous Coward · · Score: 0

      But can it clean my HOSTS file?

      Really. Where is APK when you need him?

    27. Re: Breaks some websites by Anonymous Coward · · Score: 0

      So use a vm and check out the scamware.

    28. Re:Breaks some websites by thephydes · · Score: 1

      for fuck sake someone block this wanker. He is a fucking parasite

    29. Re:Breaks some websites by lourd_baltimore · · Score: 2

      I use my HOSTS file to block these kinds of posts...

    30. Re:Breaks some websites by Rhaban · · Score: 1

      Sorry can't be a hipster.. too damn old. I've been a Mac guy since errr.. like 20 years ago now.

      So, you’ve been a hipster since before it was cool?

    31. Re:Breaks some websites by Anonymous Coward · · Score: 0

      You mean you were using Mac before it was cool?

    32. Re:Breaks some websites by y5t3m · · Score: 1

      lots of psy below. No sensible debate on this.

    33. Re:Breaks some websites by Anonymous Coward · · Score: 0

      The sad-but-funny thing is that Macs were really cool (and getting cooler) before they got popular and when they finally became popular Apple started making them crappier and crappier, which did not seem to influence their popularity (at least not negatively).

    34. Re:Breaks some websites by alex67500 · · Score: 4, Funny

      Q: Why did the hipster burn his mouth?
      A: He ate pizza before it was cool!

    35. Re:Breaks some websites by Anonymous Coward · · Score: 1

      Ahh, that is so cute.

    36. Re:Breaks some websites by Anonymous Coward · · Score: 0

      go to about:config set extensions.blocklist.enabled to false then make sure both of the Java plugins are set to ask or always activate.

    37. Re:Breaks some websites by Anonymous Coward · · Score: 0

      You know what a HOSTS file won't fix? Subluxations.

    38. Re:Breaks some websites by Anonymous Coward · · Score: 0

      APK's right though. Nobody disproved facts he used about hosts.

    39. Re:Breaks some websites by jellomizer · · Score: 1

      HTTPS isn't end all be all in security.
      It just encrypts your message and offers a secure authenticated certificate.
      Your browser has a list of trusted authenicators.
      So in terms of raw security it will just prevent people with a packet sniffer finding your information. Sure that is more secure, however most networks now have switches vs hubs which makes broadcast packets less common.
      The site authenicators charge a lot of money for these certs, and most really don't do too much to verify their true identity, and some sites will used home made certs to save money... Especially if they are working with a smaller client base who knows to ignore the big alert from the browser.

      Most of the breakins are due to people getting into the server via different ways (SQL injection, back doors on the server, back doors on an other server that has access to the existing server...) Where they can take your information from the servers. Or add malcode into the javascript where it could break other flaws in the browser, and get stuff from your own PC.

      Also defaulting to HTTPS even if you don't request it. could cause other issues. The HTTP vs HTTPS site could be very different. HTTP may be your companies poster board, and the HTTPS is for access for the customer.

      --
      If something is so important that you feel the need to post it on the internet... It probably isn't that important.
    40. Re:Breaks some websites by TangoMargarine · · Score: 1

      Shhh, you'll summon the Dark Lord of HOSTS Files!

      --
      Unity? Screw that: XFCE. Slashdot Beta? Screw that: SoylentNews. Australis? Screw that: Pale Moon. UX developers DIAF
    41. Re:Breaks some websites by Anonymous Coward · · Score: 0

      It's Jeremiah Cornelius, he posted one of these last year while accidentally leaving the Anonymous checkbox unchecked. He contributes just enough to get his karma up and then just bombards every fucking article with this bullshit. He should just be k-lined already.

    42. Re:Breaks some websites by Anonymous Coward · · Score: 0

      Q: Why did the hipster burn his mouth?
      A: He ate pizza before it was cool!

      Just curious, but when wasn't it cool?

    43. Re:Breaks some websites by Anonymous Coward · · Score: 0

      Who is the EFF think they are fooling?

      Of the 100% of sites that offer HTTP, only maybe 8% of them offer HTTPS, and that's largely Google, Twitter, and Banking sites. These sites already force HTTPS if you've enabled it.

    44. Re:Breaks some websites by nullchar · · Score: 1

      So Slashdot is hyping their new beta site, yet they allow same post by the same user over and over, even after continuous down modding.

    45. Re:Breaks some websites by hobarrera · · Score: 1

      No need for a new computer, you can run OpenBSD fine on that already.

  2. doubtful by Anonymous Coward · · Score: 1

    I don't think HTTPS will stop the NSA

    1. Re:doubtful by Big+Hairy+Ian · · Score: 1
      --

      Build a Man a Fire, and He'll Be Warm for a Day. Set a Man on Fire, and He'll Be Warm for the Rest of His Life.

  3. Apple locked Mozilla Firefox out of their platform by Anonymous Coward · · Score: 0, Flamebait

    Of course they did.. Anyone ever try to get an App on Itunes? The approval team are ran by a bunch dumb Indians who don't know their ass from a hole in the ground. The people above them are even more retarded and don't understand basic software engineering concepts. In fact the entire company, is ran by "holier than thou" pompous assholes who play god.

    It takes literally 5 minutes to deploy an App on Google Play. It takes months to get something on I-tunes.

    To All Developers: Stay far away from Apple, and hope they die the overpriced under-powered death they deserve.

    To All Developers: Stick with android and urge everyone to throw away their Apple products.

    And no I'm not RMS :(

  4. HTTPS is secure? by Anonymous Coward · · Score: 5, Informative

    http://www.theguardian.com/world/2013/sep/05/nsa-gchq-encryption-codes-security

    1. Re:HTTPS is secure? by gmuslera · · Score: 2

      HTTPS is not a guarantee, but is a good first start. They may not have your certificate (yet), and if the remote server uses forward secrecy getting it later won't decrypt your past communications. And the people wanting to know (or intercept/fake/whatever) your communication don't end in NSA/GCHQ/similars.

    2. Re:HTTPS is secure? by Anonymous Coward · · Score: 0

      HTTPS is not a guarantee, but is a good first start. They may not have your certificate (yet), and if the remote server uses forward secrecy getting it later won't decrypt your past communications. And the people wanting to know (or intercept/fake/whatever) your communication don't end in NSA/GCHQ/similars.

      Yes, HTTPS Everywhere is certainly better than nothing. But IMO the summary overstates the trust we can put in HTTPS regarding surveillance;

      "and this means that Firefox on Android with HTTPS Everywhere is now by far the most secure browser against dragnet surveillance attacks like those performed by the NSA, GCHQ, and other intelligence agencies".

      There's some big challenges ahead before we can say that.

    3. Re:HTTPS is secure? by AmiMoJo · · Score: 4, Informative

      It's not secure if they target you, but it massively increases the cost of monitoring you. Rather than just passively hoovering everything up they have to actually attack. If everyone does it their job gets hardware and more costly.

      --
      const int one = 65536; (Silvermoon, Texture.cs)
      SJW, n: "Someone I don't like, and by the way I'm a fuckwit" - AC
    4. Re:HTTPS is secure? by rvw · · Score: 1

      The question asked in the summary is whether Firefox is now safer than other mobile browsers, because of this addon. Firefox is for me the default browser on desktop and phone, because I trust it more than Chrome or Safari or IE.

    5. Re:HTTPS is secure? by Anonymous Coward · · Score: 0

      I'm curious as to why you suggest it would massively increase costs to watch https traffic for an agency that puts itself conveniently as a man in the middle for most traffic, and meanwhile can lean on CA's pretty simply to undermine https. This isn't an issue of brute force, which WOULD be expensive, but an extra relatively simple step to take to undermine the decidedly weak SSL authentication measures.

      It might be expensive for some reason I'm missing here, but from what I can see, it really doesn't look like it, any more than running SSLsniff is expensive once you've arp-poisoned a LAN.

  5. unnecessary bloat cruft by Anonymous Coward · · Score: 0

    It is really so hard to type an S?

    HTTPS Everywhere is just a huge crutch for people who are really really lazy.

    1. Re:unnecessary bloat cruft by Rosco+P.+Coltrane · · Score: 4, Insightful

      If I forget to type the S, I like having the crutch.

      It's a bit like automatic collision avoidance braking systems that are starting to appear on cars these days: you might say it's a huge crutch for people who are too lazy to drive properly and maintain distances, but you know what? it's a good idea I'd like to have it nonetheless, in case my concentration lapses.

      --
      "A door is what a dog is perpetually on the wrong side of" - Ogden Nash
    2. Re:unnecessary bloat cruft by infogulch · · Score: 5, Insightful

      Nonsense. If you're browsing the web and following a bunch of links, you would have to long press the link to copy it, long press to paste it in the url bar, edit the url to add the S (this is mobile, so moving the cursor directly between the "p" and the ":" is non-trivial), and hit enter... for every link you follow.

      You can't just click the link and edit the url after the page loaded because you've already given away the url path, url query, cookies, referrer, etc to anyone snooping your connection. And what if a site doesn't support https and instead redirects you to its' http variant? For some people they'd rather it fail to load than load insecurely. There are many reasons to use such an extension.

    3. Re:unnecessary bloat cruft by viperidaenz · · Score: 1

      Do you re-type links on a page instead of clicking them?

    4. Re:unnecessary bloat cruft by fuzzyfuzzyfungus · · Score: 2

      In some, but not all, cases it will also rewrite any http links within the site itself, which is a much more useful feature. People certainly do forget when typing URLs; but manually checking, copying, pasting, and editing links within a page would be a huge pain in the ass.

      Now, as for why a site operator would have non-ssl links to parts of their site on parts of their site accessed over ssl, that's a question for when I'm feeling less rageful.

    5. Re:unnecessary bloat cruft by Cimexus · · Score: 2

      I have one of those. I do actually like having it, for the reasons you say. Though in winter I do note it gets confused by snowbanks on the side of the road and occasionally cars in other lanes. Beep beep beeeeeeeep. Ahhhhhhh what?!

    6. Re:unnecessary bloat cruft by AC-x · · Score: 1

      Nonsense. If you're browsing the web and following a bunch of links, you would have to long press the link to copy it, long press to paste it in the url bar, edit the url to add the S (this is mobile, so moving the cursor directly between the "p" and the ":" is non-trivial), and hit enter... for every link you follow.

      And don't forget the waiting for it to fail and changing it back to HTTP:// when you get a server that doesn't have https.

    7. Re:unnecessary bloat cruft by AK+Marc · · Score: 1

      When I type www.google.com and my browser sends me to HTTP://www.google.com, why would it be be a crutch to have it send me to HTTPS:// instead?

      Yes, directing people to https when they click http on a page is a crutch, but for the designers, who obviously don't care, not for the user.

  6. how appropriate.. by stillpixel · · Score: 2

    comment spam on an article about how something is so secure.

    1. Re:how appropriate.. by Anonymous Coward · · Score: 0

      Comment spam brought to you by SPAMS Everywhere.

    2. Re:how appropriate.. by stillpixel · · Score: 0

      Mr. Bun: Morning.

      Waitress: Morning.

      Mr. Bun: What have you got, then?

      Waitress: Well there's egg and bacon; egg, sausage and bacon; egg and spam; egg, bacon and spam; egg, bacon, sausage and spam; spam, bacon, sausage and spam; spam, egg, spam, spam, bacon and spam; spam, spam, spam, egg and spam; spam, spam, spam, spam, spam, spam, baked beans, spam, spam, spam and spam; or lobster thermidor aux crevettes, with a mornay sauce garnished with truffle paté, brandy and a fried egg on top and spam.

      Mrs. Bun: Have you got anything without spam in it?

      Waitress: Well, there's spam, egg, sausage and spam. That's not got MUCH spam in it.

      Mrs. Bun: I don't want ANY spam.

      Mr. Bun: Why can't she have egg, bacon, spam and sausage?

      Mrs. Bun: That's got spam in it!

      Mr. Bun: Not as much as spam, egg, sausage and spam.

      Mrs. Bun: Look, could I have egg, bacon, spam and sausage, without the spam.

      Waitress: Uuuuuuggggh!

      Mrs Bun: What d'you mean, uugggh! I don't like spam.

      Vikings:
      (singing) Spam, spam, spam, spam, spam ... spam, spam, spam, spam ... lovely spam, wonderful spam ...
      (Brief shot of a Viking ship)

      Waitress: Shut up. Shut up! Shut up! You can't have egg, bacon, spam and sausage without the spam.

      Mrs. Bun: Why not?

      Waitress: No, it wouldn't be egg, bacon, spam and sausage, would it?

      Mrs. Bun: I don't like spam!

      Mr. Bun: Don't make a fuss, dear. I'll have your spam. I love it. I'm having spam, spam, spam, spam, spam ...

      Vikings: (singing) Spam, spam, spam, spam ...

      Mr. Bun: ... baked beans, spam, spam and spam.

      Waitress: Baked beans are off.

      Mr. Bun: Well can I have spam instead?

      Waitress: You mean spam, spam, spam, spam, spam, spam, spam, spam, spam, spam?

      Vikings: (still singing) Spam, spam, spam, spam ... (etc.)

      Mr. Bun: Yes.

      Waitress: Arrggh!

      Vikings: ... lovely spam, wonderful spam.

      Waitress: Shut up! Shut up!

      (The Vikings shut up momentarily. Enter the Hungarian.)

      Hungarian: Great boobies honeybun, my lower intestine is full of spam, egg, spam, bacon, spam, tomato, spam ...

      Vikings: (Singing) Spam, spam, spam, spam ...
      (A policeman rushes in and bundles the Hungarian out.)

      Hungarian: (As he leaves) My nipples explode ...
      (Cut to an historian) Caption, super. "A HISTORIAN"

      Historian: Another great Viking victory was at the Green Midget café at Bromley. Once again the Viking strategy was the same. They sailed from these fiords here, (indicating map with arrows on it) assembled at Trondheim and waited for the strong north-easterly winds to blow their oaken galleys to England whence they sailed on May 23rd. Once in Bromley they assembled at the Green Midget café and spam selecting a spam particular spam item from the spam menu would spam, spam, spam, spam, spam ...

      Vikings: (singing) Spam, spam, spam, spam, spam, lovely spam, wonderful spam. Lovely spam, wonderful spam ...

  7. Haha by Anonymous Coward · · Score: 1

    Too bad it doesn't have anything for spam bot control.

    http://postimg.org/image/ryho8lbfj/

  8. not even security by Anonymous Coward · · Score: 1

    Doesn't mitigate any vulnerabilities already present in the browser. Doesn't add any encryption beyond what's already provided by the web servers.

    1. Re:not even security by Maximilianop · · Score: 1

      No only that.
      Quote from their site "The HTTPS Everywhere extension fixes these problems by using a clever technology to rewrite requests to these sites to HTTPS"
      What is this clever technology?
      Could it be a hook on every single request, analysing the host to "know" if the request "should be rewritten as HTTPS"
      How do they decide when a server has HTTPS capabilities? Are they just "probing" each webserver? Do they have a DB? Do website owners have a say in this?

      What is disabling the extension from logging and saving a DB on every single request you send to the web?
      What is disabling the extension from saving your username and passwords for sensible sites?

      More than securing your phone browser, this seems like the definition of spyware to me...

      --
      The Universe is shrinking all around my head.
  9. Re:Apple locked Mozilla Firefox out of their platf by stillpixel · · Score: 1

    Honestly.. I liked what the comment spammer said more. Less whine and more vomit..

  10. Re:Apple locked Mozilla Firefox out of their platf by Anonymous Coward · · Score: 0

    I think they might be talking about MyCleanPC but I can't be sure.

  11. Considering... by Anonymous Coward · · Score: 3, Insightful

    People most likely don't type HTTP to begin with... I don't type http://facebook.com... just facebook.com. Google.com. slashdot.org. etc...

    The S isn't just an extra S...

    1. Re:Considering... by Anonymous Coward · · Score: 0

      None of the above. They type facebook, google or slashdot in the search bar.
      If they ever use more than one page that is. Otherwise they just hit reload.

    2. Re:Considering... by bipbop · · Score: 1

      For every site I use regularly, I have a one- or two-letter shortcut. When I want to use Slashdot, I hit ^L to focus the URL bar, type the letters sd, and then hit enter.

      If I wanted to use Slashdot with HTTPS (which I don't), I would simply change the URL associated with that shortcut to say https instead. It would be zero extra letters for me.

  12. Re:Apple locked Mozilla Firefox out of their platf by stillpixel · · Score: 1, Offtopic

    About 6 months ago the angry Android fanboi above these comments was rearranging his "apartment" in the "lower-level" of his parents home when he got his app rejection notice from Apple for his awesome new game "Flamin' Fowl".. the note contained a remark something to the effect that his app was of less quality than those Chinese knock off apps.

    Since then he has with drawn even more.. he even stopped playing Magic.

  13. Re:Apple locked Mozilla Firefox out of their platf by stillpixel · · Score: 1

    I think MyCleanAndroid would have been a better app to flog with this article. Really.. what good does it do to https on your browser when the apps you have are full of holes and barely examined before being placed on the Google Play app store.

  14. Idiot by Anonymous Coward · · Score: 5, Funny

    It was highly illogical for you to blockquote all of that bullshit, Spock. I am unsure which one of you is the dumber one.

    1. Re:Idiot by Gadget27 · · Score: 1

      Fascinating

  15. Re:Apple locked Mozilla Firefox out of their platf by Anonymous Coward · · Score: 1

    And no I'm not RMS :(

    RMS runs Hurd-Mobile OS on his phone.

  16. Dear MyCleanPC, by somenickname · · Score: 4, Funny

    I will admit that I was skeptical that a piece of software could cure my cancer, bring back my wife and prevent me from beating my daughter but, based on dozens of posts on Slashdot, I'm willing to give it a try.

    1. Re:Dear MyCleanPC, by stillpixel · · Score: 5, Funny

      Wow. It could also be the end of Country music as we know it.

    2. Re:Dear MyCleanPC, by somenickname · · Score: 3, Funny

      Well, nowhere in the glowing reviews did I see that it would also bring back my dog so, country music still has its place.

    3. Re:Dear MyCleanPC, by Anonymous Coward · · Score: 0, Funny

      I will admit that I was skeptical that a piece of software could bring back my cancer, prevent me from beating my wife and could cure my daughter but, based on dozens of posts on Slashdot, I'm willing to give it a try. As it is even more versatile than you give it credit for.

      GO BRONCOS!

    4. Re:Dear MyCleanPC, by stillpixel · · Score: 1

      Please don't bring sports into this conversation, you'll scare the neckbeards.

    5. Re:Dear MyCleanPC, by oscrivellodds · · Score: 1

      And don't forget your truck!

    6. Re:Dear MyCleanPC, by ArchieBunker · · Score: 1

      Any half competent admin could write some sort of filter script to get rid of this spam. I give this domain another year or so before it starts to cost Dice money and they park it.

      --
      Only the State obtains its revenue by coercion. - Murray Rothbard
    7. Re:Dear MyCleanPC, by Anonymous Coward · · Score: 0

      With the gun rack and the obligatory bumper sticker that has a picture of an American flag and the words "These colors don't run!"

      Yeee Hawwwww!!!

  17. Re:Apple locked Mozilla Firefox out of their platf by stillpixel · · Score: 1

    The above commenter is quite serious about their software fanboi-ism it verges on the realm of being a Linux anti-microsoft zealot.

  18. Depends on the threat model, doesn't it? by fuzzyfuzzyfungus · · Score: 5, Insightful

    'Secure' isn't really something where you can just boil it into a number between 1 and 100 and call it a day. If you are worried about attackers sniffing the wire, a plugin that enforces SSL use is a major advantage. If you are worried about being hit with a zero day by the guy on the other end of the wire, it's entirely irrelevant.

    1. Re:Depends on the threat model, doesn't it? by Anonymous Coward · · Score: 4, Funny

      Secure = 100;
      itaday();

    2. Re:Depends on the threat model, doesn't it? by somenickname · · Score: 5, Insightful

      I loathe to say this but, HTTPS Everywhere is security theater. It makes your browser have a green icon where it otherwise might not but, that green icon is just an illusion of security. Considering recent revelations about the NSA, I would assume all SSL certificates are compromised. Like, literally, all of them. If the trust chain has been compromised by one party (the NSA), I would assume it compromised by all parties.

    3. Re:Depends on the threat model, doesn't it? by Anonymous Coward · · Score: 1

      ""Apple has locked Mozilla Firefox out of their platforms.""

      Or you could be like Apple and deny any secretive co-operation with spying agencies, then block out Mozilla, and I guessing anyone else from locking down your OS/Apps from giving away your data. And the Apps that your downloading tracks anything you do. SO unless you have a phone with no Apps or any hidden programming to collect data it's not going to matter what you do to secure your data from spying by the NSA or 3rd party sources.

      The EFF had to have known about the NSA and other agencies to begin with, and I seriously distrust any claims they make over security from spying. Its one thing to be a small org., but they only go after high profile cases, and I can almost promise you they know a lot more then there publicly leading people to believe. The idea behind what there about is great, but being arrogant or making people think you are, kinda throws that out of balance.

    4. Re:Depends on the threat model, doesn't it? by kasperd · · Score: 4, Informative

      I would assume all SSL certificates are compromised. Like, literally, all of them.

      No amount of snooping on the network would compromise a private key, which never leaves the server in the first place. Thus the only way you could possibly compromise the certificate, would be if you put an invalid public key in the certificate in the first place. Since that would be immediately obvious to any server owner paying enough attention, it is safe to assume that compromising all certificates cannot be done without being detected. If they literally compromised all of them, it would only take one single security aware server administrator to notice it.

      This is why we should focus much more on protocols that are secure against passive attacks, but not against active attacks. Systematic passive attacks can be pulled off without detection. Systematic active attacks cannot. Protection against active attacks is much harder and is the reason we have the CA system. It is not that protecting against active attacks is a bad idea, it is just that it is so hard that much communication isn't protected. Opportunistic encryption with security against active attacks could be done without needing certificates. If on top of that you do perform certificate validation on the most critical sites after you have established a connection with only the opportunistic protection, then you do get protection against active attacks. In order for this to make sense, it is important that until you do perform an active attack, you cannot know if the connection has been secured against active attacks.

      Both types of connections will benefit by being indistinguishable from the other to a passive adversary.

      The connections with only passive security benefits because it is now easier to do encryption, and moreover being indistinguishable from the minority of connections with active security protects you from systematic active attacks. This is because systematic attacks are bound to hit protected connections once in a while, so they cannot go undetected.

      The connections with the full active security also benefits because they are now attracting less attention. They will be a minor fraction of a much larger amount of encrypted connections. A passive adversary cannot know which of the connections have active security and are likely to contain the juicy stuff.

      --

      Do you care about the security of your wireless mouse?
    5. Re:Depends on the threat model, doesn't it? by Anonymous Coward · · Score: 0

      You blasphemous fool! How dare you declare variables with a leading uppercase letter.

    6. Re:Depends on the threat model, doesn't it? by AmiMoJo · · Score: 5, Insightful

      Even if all certificates are compromised they are still worth using. Instead of passively collecting all that data the NSA/GCHQ has to perform a man-in-the-middle attack using a server that is geographically closer to you than the one they are spoofing. It costs them more time and money, limits their ability to spy on everyone all the time and requires them to maintain those servers. MITM attacks can be detected too, and in fact Chrome has made some progress on that with pinned certificates. I think there is a Firefox plugin that does something similar.

      There are real and measurable benefits to using HTTPS, it's not just theatre.

      --
      const int one = 65536; (Silvermoon, Texture.cs)
      SJW, n: "Someone I don't like, and by the way I'm a fuckwit" - AC
    7. Re:Depends on the threat model, doesn't it? by drinkypoo · · Score: 1

      Even if all certificates are compromised they are still worth using. Instead of passively collecting all that data the NSA/GCHQ has to perform a man-in-the-middle attack using a server that is geographically closer to you than the one they are spoofing. It costs them more time and money,

      And whose money is that? Oh, it comes from the poor and the middle class, who actually pay taxes.

      --
      "You're right," Fisheye says. "I should have set it on 'whip' or 'chop.'"
    8. Re:Depends on the threat model, doesn't it? by Anonymous Coward · · Score: 0

      Even if all certificates are compromised they are still worth using. Instead of passively collecting all that data the NSA/GCHQ has to perform a man-in-the-middle attack using a server that is geographically closer to you than the one they are spoofing. It costs them more time and money, limits their ability to spy on everyone all the time and requires them to maintain those servers. MITM attacks can be detected too, and in fact Chrome has made some progress on that with pinned certificates. I think there is a Firefox plugin that does something similar.

      There are real and measurable benefits to using HTTPS, it's not just theatre.

      You overstate the case. It simply requires spending a tiny bit more of their virtually unlimited budget and some NSLs to be given taps to the servers they want info from.

    9. Re:Depends on the threat model, doesn't it? by Anonymous Coward · · Score: 0

      If they have compromised a root certificate they could use a man-on-the-side ("warp speed") attack and ensure that your request to https://nefarous-site.com gets routed more quickly via their own infrastructure than via the correct route. They have a compromised root cert that the browser accepts as genuine, they create their own apparently valid cert for nefarious-site.com and your browser thinks all is well. That's why the Perspectives extension is useful, because it checks for certificate consistency. (Of course, it doesn't help if they're deploying their MOTS attack all the time, but then you'd think the nefarious-site.com admins would notice the unusual drop off of traffic.

    10. Re:Depends on the threat model, doesn't it? by Anonymous Coward · · Score: 0

      ...but it still means the NSA have to take an active step to get your data, as opposed to just getting it given to them for free. I'd rather it cost them $1 to get my data then 0$.

    11. Re:Depends on the threat model, doesn't it? by jafiwam · · Score: 5, Insightful

      I loathe to say this but, HTTPS Everywhere is security theater. It makes your browser have a green icon where it otherwise might not but, that green icon is just an illusion of security. Considering recent revelations about the NSA, I would assume all SSL certificates are compromised. Like, literally, all of them. If the trust chain has been compromised by one party (the NSA), I would assume it compromised by all parties.

      While this is true, chances are SLL Certificates still work well enough to keep the other nerd at the coffee shop from stealing your WoW forum account credentials.

      No single person, ever, anywhere, has been able to single handedly defend themselves from the government of the place they reside. If the Government wants the account, they'll get it through twisting laws and sending the cops, not by snooping on it.

      SSL protects against run of the mill crime. And, it does that well.

    12. Re:Depends on the threat model, doesn't it? by kasperd · · Score: 1

      They have a compromised root cert that the browser accepts as genuine, they create their own apparently valid cert for nefarious-site.com and your browser thinks all is well.

      Compromising a CA certificate and compromising the certificate of an individual website is two very different situations. On average it is harder to compromise a CA certificate than that of an individual website. But for both types there is variation in difficulty. I have no doubt it is a lot easier to compromise the certificate of the most insecure CA than that of the most secure website. And if you have compromised one single CA certificate, you can use it for most of the active attacks, you want to perform. So it is mostly pointless to go for the certificates of individual websites.

      MitM attacks using a compromised CA certificate done by governments is not unheard of. I think it was only a couple of months back I last saw a browser security update to get rid of a CA certificate, which was being abused by a government (in a European country AFAIR).

      The point is, that sort of attack is discovered, if performed systematically. And they are mitigated as they happen, but after each mitigation there will still be easy targets among the remaining CAs.

      That's why the Perspectives extension is useful, because it checks for certificate consistency.

      True. Though you could achieve much of the same effect with less needs for infrastructure through certificate pinning.

      --

      Do you care about the security of your wireless mouse?
    13. Re:Depends on the threat model, doesn't it? by Anonymous Coward · · Score: 0

      Maybe a stupid question, but...

      What is certificate pinning?

    14. Re:Depends on the threat model, doesn't it? by Anonymous Coward · · Score: 0

      secure = 100;
      it_a_day();

      commit -m 'Renamed identifiers to conform with coding standard.'

    15. Re:Depends on the threat model, doesn't it? by AmiMoJo · · Score: 1

      So what you are saying is that we just give up our rights and freedoms in order to pay a bit less tax. Well, no.

      Anyway, the cost will be made astronomical, so putting up taxes wouldn't help. They will simply have to stop mass collection of data once everything uses encryption.

      --
      const int one = 65536; (Silvermoon, Texture.cs)
      SJW, n: "Someone I don't like, and by the way I'm a fuckwit" - AC
    16. Re:Depends on the threat model, doesn't it? by heypete · · Score: 1

      See http://security.stackexchange.... and https://www.owasp.org/index.ph...

      In short: a site can declare that it only uses one (or more) public keys on its secure sites and that this declaration is valid for a certain time period. Browsers that support pinning will check to see if those public keys (and no others) are being used during that validity period. If the key were to suddenly change, even if it's otherwise valid (e.g. issued by a trusted CA), the browser would complain that something is wrong.

      This prevents rogue or compromised CAs from issuing certificates to sites that used pinned certificates (at least for the duration of the validity period).

      For example, Google Chrome comes hard-coded with the public keys for Google sites. If an otherwise-valid certificate were created for Google sites (such as when the DigiNotar CA was compromised), Chrome would refuse to connect to any server using it because it does not match the built-in pinned value.

    17. Re:Depends on the threat model, doesn't it? by Anonymous Coward · · Score: 0

      Good point, surrender is much cheaper at first.

    18. Re:Depends on the threat model, doesn't it? by Anonymous Coward · · Score: 0

      I'm not sure how you can jump from the NSA having all SSL certs compromised to "anyone who wants to attack my traffic has all SSL certs compromised". It's like suggesting that because your ex has a key to your door locks, everyone has keys to your door locks.

      SSL won't stop the NSA, but it will stop the skiddy at starbucks running wireshark from scooping up your password. The REAL downfall of SSL, however, is that it WON'T stop the skiddy at starbucks who's running wireshark AND SSLSniff.

      That's where tools like namecoin or convergence come in handy, but in my experience the latter is slow, and the former isn't exactly used heavily, especially on sites where the data transmitted is probably more private than on the sites that use it.

    19. Re:Depends on the threat model, doesn't it? by OdinOdin_ · · Score: 1

      Wooossshhhh!

      He (somenickname) is talking about the global CA system where all 1000 CAs are equally trusted, so the NSA only need to convince one to reissue a certificate (based on a private key the NSA provided) in the name of the target website they wish to intercept.

      The content consumer has no way of knowing if the SSL cert that is being used for the HTTPS connection is the one using the site owner's private key or the one using the NSA's private key. So this is why simply having a green light because you switched to SSL is security theatre.

      But you (kasperd) go on an rant about other matters.

      The projects such as SSL Observatory https://www.eff.org/observator... and Convergence http://convergence.io/index.ht... and http://tech.slashdot.org/story... combined with DNSSEC (which somewhat has the same problems as the CA system, but useful to allow deployment for low security websites without paying sign-my-certificate tax).

  19. Re:Apple locked Mozilla Firefox out of their platf by stillpixel · · Score: 1

    Replace the above comment with some drivel about Creationism and it will be just as useful.

  20. Not when by Anonymous Coward · · Score: 1

    NSA has a copy of the private keys as well.

  21. What the frak? by Anonymous Coward · · Score: 0

    WTF is with the my clean PC BS? Can't the posts be deleted? For the first time I see the death of /. coming around the bend. So sad.

    1. Re:What the frak? by stillpixel · · Score: 2

      Obviously it's the NSA's attempt at obscuring the news of this amazing new plugin for a browser on a phone...

    2. Re:What the frak? by curty · · Score: 3, Insightful

      For the first time I see the death of /. coming around the bend.

      You must be new here.

    3. Re:What the frak? by firex726 · · Score: 1

      Not the first time either... IDK why the admins can't impose a rule about duplicate posts in the comments.

      How many cases are there that one user would need to make a dozen identical posts of over 1000+ words?

    4. Re:What the frak? by Cenan · · Score: 3, Interesting

      You're confusing User with Customer. We're the users, advertisers are the customers.

      "Can remove spam" and "will remove spam" are not the same thing. They absolutely, trivially could prevent this kind of spam - but why would they? Nobody at Dice cares! In all the years I've come here I've never seen the admins do anything remotely resembling administration of their site.

      Another comment on a thread, no matter how trivial or spammy, enforces the illusion of a site that is still alive. This illusion is used to make the search indexers think that something of relevance is going on at the site, and rate it higher, which in turn exposes yet more of Dice's advertising. The key to proper SEO is novel content, the trick is that the content doesn't have to be at all relevant or even coherent, it just has to be new and Google will swallow it like a junior at the prom with the star jock.

      Whenever some moron codes up a new incarnation of retardo-bot and launches it in a flurry of masturbation, a whole host of /. users will flock around and comment on the spam. It's a viscous cycle and Dice has no incentive to stop it.

      Short story even shorter: Dice runs the site. Dice profits from not removing spam posts.

      --
      ... whatever ...
    5. Re:What the frak? by UberVegeta · · Score: 2

      It's a viscous cycle

      Maybe we should sticky this.

      --
      I knew I needed to stop reading Slashdot and finish my PhD when I started to miss articles by Bennett Haselton.
    6. Re:What the frak? by Cenan · · Score: 1

      We really should! In my defense I work with fluid mechanics so viscosity comes up a lot.

      --
      ... whatever ...
    7. Re:What the frak? by Desler · · Score: 1

      There is a duplicate post filter. It's just extremely easy to bypass.

    8. Re:What the frak? by Somebody+Is+Using+My · · Score: 1

      On the other hand, I would feel extremely uncomfortable if they /did/ moderate the comments. Because that sort of activity can quickly snowball from their just deleting spammer accounts/comments to zapping comments that they disagree with or feel is not in the company's interests. Especially since the users do such a good job of cleaning up the trash themselves (honestly, except on the occassions when I read at comment level 0, I never even SEE these MyCleanPC or other spam/troll comments anymore).

      I wish Dice did better editing the SUBMISSIONS (even if all they did was correct any typos or prevent obvious dupes) but I am far happier if they keep their hands off the comments themselves.

    9. Re:What the frak? by jbmartin6 · · Score: 1

      Doesn't' beta.slashdot.org count as something resembling administration?

      --
      This posting is provided 'AS IS' without warranty of any kind, implied or otherwise.
    10. Re:What the frak? by Cenan · · Score: 1

      I guess for some, very broad, interpretations of the word "administration". Kind of like how a steaming pile of dog shit resembles chocolate cake.

      --
      ... whatever ...
    11. Re:What the frak? by SpanglerIsAGod · · Score: 1

      I agree with this. The moderation here is designed to make deleting or blocking posts unnecessary, and I like that.
      I also like that you can't edit posts since lots of people like to troll and change their post after it get's responses to make responders look like idiots.

      --
      War doesn't show who is right - just who is left.
    12. Re:What the frak? by Cenan · · Score: 1

      On the other hand, I would feel extremely uncomfortable if they /did/ moderate the comments. Because that sort of activity can quickly snowball from their just deleting spammer accounts/comments to zapping comments that they disagree with or feel is not in the company's interests. Especially since the users do such a good job of cleaning up the trash themselves (honestly, except on the occassions when I read at comment level 0, I never even SEE these MyCleanPC or other spam/troll comments anymore).

      Yes, there are plenty of other places on the 'net where anal mods have free roam, we don't need another. I don't agree that the users here do a good job of cleaning up. They do a very good job of promoting circle jerking by instantly promoting mundane comments to +5 Funny/Insightful/Interesting for agreeing with them. I always browse at -1 for that very reason, once in a while a -1 comment will actually have something novel to say.

      I wish Dice did better editing the SUBMISSIONS

      I agree! But that is a problem to which my original explanation also applies. They've got no reason to clean it up. Posting craptastic submissions just spawns threads much like this one, where people discuss how god awful /. has become and how much better "the olden days" were. /. is unique in the way it handles news aggregation and user composed content. Dice has just elected to take a dump all over the concept to maximize profits. They could do something about the shit that keeps dripping on us, but why should they when we keep coming?

      I find that blocking submissions from Roblimo actually takes care of most of the idiocy that gets posted, at least the obvious for-profit stories goes away. Now they just need a spell checker, if they get that right we could go for gold and demand they also fact check.

      --
      ... whatever ...
    13. Re:What the frak? by azalin · · Score: 1

      For the first time I see the death of /. coming around the bend.

      You must be new here.

      Amen to that

    14. Re:What the frak? by danomac · · Score: 1

      It's a viscous cycle and Dice has no incentive to stop it.

      Short story even shorter: Dice runs the site. Dice profits from not removing spam posts.

      I guess Dice is throwing stuff at the site and is waiting to see what sticks?

    15. Re:What the frak? by Anonymous Coward · · Score: 0

      > It's a viscous cycle

      The only way to beat a viscous cycle is to just go with the flow.

    16. Re:What the frak? by n6kuy · · Score: 1

      Does Netcraft confirm it?

      --
      If you disagree with me on social issues, then it's pretty clear that you are a narrow-minded bigot.
  22. What's worse? by Anonymous Coward · · Score: 1

    I'm not sure what's worse: the My Clean PC spam, or the hipsters that feel the need to reply to it every chance they can and tell us all about how they use Macs and how wonderful of people they are for doing so.

    1. Re:What's worse? by stillpixel · · Score: 0

      wow.. hey.. do you use a Mac? You know if you got a PC, you too could use MyCleanPC.. all the hip kids are using it on their Android phones because the go to spammy sites in their default browsers instead of getting Firefox and that amazing https plugin

    2. Re:What's worse? by Anonymous Coward · · Score: 0

      Your ignorant Apple fanboy comments are really beside the point. It's a fact that Apple won't allow any other browser to be installed on iOS and this increasingly shows as a weakness not only with regard to the possibilities for installing the https extension but also in the case of creating custom AdBlock filters, which are a must for any users in the European Union now after the cookie warning directive has come into force. Effectively it means that the users of expensive iOS devices are forced to look at cookie warning banners and popups every time they browse to a new website while Android users can simply set up a new filter in the AdBlockPlus extension for their Firefox and never see a cookie warning again.

      How does it feel I wonder for all those European Apple users, who paid through the nose to buy an expensive shiny iToy only to find out that the browser performance in terms of not being able to remove annoying popups and cookie warnings is actually far worse than on Android with Firefox installed?

    3. Re:What's worse? by stillpixel · · Score: 1

      I have Chrome installed on my iPhone, so I guess FF is just doing something wrong.

    4. Re:What's worse? by Anonymous Coward · · Score: 0

      No you don't. You have a Chrome-skinned Safari installed on your iPhone.

      There will never be extensions like HTTPSEverywhere or AdBlockPlus available for your pathetic Chrome-skin for iPhone.

  23. NSA has the ssl keys by hipsterdufus · · Score: 4, Insightful

    The NSA likely has keys from all the major SSL cert vendors, rendering this "spamvertisement" moot. HTTPS does not mean that you're secure from everybody. It means you've added a layer of security that will thwart MOST prying eyes, but those that really want to know what you're doing WILL know what you're doing.

    What a silly thing to appear on slashdot.

    1. Re:NSA has the ssl keys by Anonymous Coward · · Score: 0

      It means you've added a layer of security that will thwart MOST prying eyes

      Your ISP doesn't just send your communication to random individuals. HTTPS specifically prevents the ISP from listening in. Everyone was already out of of the loop.
      The problem is that your ISP is a man in the middle and HTTPS only protects against that if you handle the certificate in a proper manner.
      If you don't trust your ISP you have a pretty big security issue.

    2. Re:NSA has the ssl keys by Jane+Q.+Public · · Score: 4, Insightful

      "What a silly thing to appear on slashdot."

      Why is it silly? It still means that most people will be more secure, most of the time.

    3. Re:NSA has the ssl keys by Anonymous Coward · · Score: 0

      Note that IF the NSA had such keys and IF they ever used them to MitM a connection, the person they used them on could (even by accident) collect conclusive proof that a particular SSL CA had been compromised in this way. Of course they wouldn't know what they had at the time, but later by comparing with others they would know. Some of the browser add-ons will already do this for you, because why not.

      So IF they could do this it would never make sense to do it for anything other than a high value one shot, because if you use it to find out whether Joe Bloggs got that email from his sister yet and he happens to collect the SSL proofs that show what you're doing then you've destroyed a VERY VALUABLE and arguably IRREPLACEABLE intelligence resources to get something almost worthless.

      Worse, if the target is using a distributed strategy, the alarms go off for them immediately. You've lied to them, but you have to lie to everybody, everywhere or the distributed strategy will detect an inconsistency. And if you lie to everybody then EVERYBODY IN THE WORLD can now detect that you've got your own keys and are snooping on people.

      So, is it possible that they have such keys? Sure. Would they use them? Probably not. It's like being Israel. You've got the bomb, but you can't threaten to use it because then your "friends" (Europe in this example) would tear you to pieces.

    4. Re:NSA has the ssl keys by dvdkhlng · · Score: 5, Informative

      The NSA likely has keys from all the major SSL cert vendors, rendering this "spamvertisement" moot. HTTPS does not mean that you're secure from everybody. It means you've added a layer of security that will thwart MOST prying eyes, but those that really want to know what you're doing WILL know what you're doing.

      Having the keys from multiple SSL cert vendors does not help a bit (and having the keys from many vendors isn't much better than having the keys of a single vendor). It does NOT magically allow you to decrypt SSL traffic from servers whose host key was signed against that cert vendor's certificate!

      To decrypt traffic of multiple SSL websites requires you to obtain the private part of the SSL host keys from all the web-servers themselves. Note that web server host keys are signed via signing requests that do not contain a copy of the private key, so even when the cert vendors (CAs) are hacked, you cannot directly listen in on SSL communication. When the servers implement Perfect Forward Secrecy, then even obtaining a copy of the server's host key won't help as each connection uses a temporary key that's exchanged via Diffie Hellman Key Exchange, a method that generates a key shared between two hosts, that (somewhat counter-intuitively) cannot be deduced by sniffing the traffic between those two participants.

      What you can still do is to set up a MITM attack: you set up your own intermediate server with its own host key and sign your host key(s) using one of the SSL vendor's certs that you obtained. Then you redirect all traffic to the servers that interest you via your server (i.e. proxying all SSL connections) and then obviously in the process you obtain the cleartext of all SSL sessions running via your server.

      However, the MITM attack is much more difficult to deploy and scale than simple monitoring and recording IP data. Also skilled users will easily detect the MITM attack, as the host key's public part of the servers in question will suddenly change. There are firefox extensions to check for these signs of a MITM. Even SSL Everywhere has a checker built in (via the SSL Observatory). Or try Certificate Patrol.

    5. Re:NSA has the ssl keys by Anonymous Coward · · Score: 0

      This is something that the SSL Observatory should be able to deal with, right?

    6. Re:NSA has the ssl keys by thegarbz · · Score: 2

      All this allows you to do is create a MITM attack which won't be detected by your browser. However another plugin like Perspectives will compare the SSL cert you were served with notarys from several other sources. Since it's incredibly difficult to MITM a system in a way that the same middleman is presented to everyone it creates yet another layer of protection.

      Is it perfect? No. But sure beats the security of ASCII based traffic we're spewing everywhere right now.

    7. Re:NSA has the ssl keys by Anonymous Coward · · Score: 0

      Perspectives is interesting - I use it, and I see it come up red a surprising amount of the time. I would wear a tinfoil hat, but I know perfectly well they've got to the tinfoil manufacturers as well and ensured that any tinfoil you buy has a little lattice of brainwave detectors and antennae to transmit your thoughts directly back to Langley. Hell, it makes their job even easier! :-)

    8. Re:NSA has the ssl keys by jafiwam · · Score: 1

      You are assuming your software doesn't send the private key somewhere when you aren't looking.

    9. Re:NSA has the ssl keys by Anonymous Coward · · Score: 0

      Do you really think it's that hard to set up MTM if you have gigantic servers and systems sitting on every backbone connection there is? Backdoors in every router there is?

    10. Re:NSA has the ssl keys by Mathieu+Lu · · Score: 1

      nonsense.. that's a blanket statement that doesn't mean anything, implying that we should only consider absolutely secure solutions that will protect against all attacks. There is no one size fits all. Adding a layer of security that "will thwart MOST prying eyes" is well worth it, just don't expect it to be bullet proof and understand how it works, what it protects from.

      If I recall correctly one of the initial aims of "https everywhere" was to protect people using public wifi. Hijacking FB accounts on public wifi became a common attack (and many others). It's a low-hanging fruit that encouraged a lot of websites to enable and fix their SSL for everyone.

      Not to mention.. even if the NSA had keys from the major SSL cert vendors: you probably meant: they have the private key of Google/Facebook/etc, since the cert vendor key itself only signs the cert, it does not provide the private key that encrypts the communication.

      Even then, don't use Google/FB. A lot of Snowden docs talked about tracking using the IDs from those services, although nothing has indicated that they have private keys of google/fb, it assumed that google/fb traffic was non-SSL. It's also a big leap to assume that they can generate/obtain private keys for other non-cloud services.

    11. Re:NSA has the ssl keys by Anonymous Coward · · Score: 0

      I would wear a tinfoil hat, but I know perfectly well they've got to the tinfoil manufacturers as well and ensured that any tinfoil you buy has a little lattice of brainwave detectors and antennae to transmit your thoughts directly back to Langley.

      That's why I'm feverishly hammering this down to foil thickness...

    12. Re:NSA has the ssl keys by Luke+has+no+name · · Score: 2

      What a silly thing to appear on slashdot.

      What a silly thing to say! Most of the time, it's not the NSA I'm worried about, it's the ISP or the creeper next to me on the open wifi network. Most people don't have an ipsec tunnel to their home network for secure wifi access, so this isn't a bad thing at all.

      Issues with CA's and the NSA are real, but don't get huffy-puffy about a practical addon being brought up on /.

    13. Re:NSA has the ssl keys by Anonymous Coward · · Score: 0

      Sigh. Oh, how I wish you were right in practice.

      I run cert patrol, and some other pretty complex monitoring software... sort of... "meta dns with special proxy" services that can do some pretty complex logging, redirecting, filtering... webserver host header tampering with other headers being modified.

      (Hah, you idiot web devs thought you could set HTTPOnly on cookies as if fucking meant something)

      There's one big problem with cert patrol, and it's "the cloud".

      Amazon EC2, Google, pretty big SaaS apps... you name it. On big platforms the certificate often changes every page load as a different server handles the request with its own validly signed cert.

      In the case of something like Google Plus, you often get five or six cert changes every time you visit.

      You're forced to completely ignore the changes to use the most foundational part of the infrastructure.

      Sure, you could monitor for things like "a new issuing authority" -- but it kind of defeats the point.

      SSL Observatory is great for certs that actually can be pinned -- but unfortunately, these days that's pretty much just small sites.

      The best you might hope for with Observatory is catching an attack after the fact. And frankly, the observatory isn't robust or diverse enough to survive a man-in-the-middle.

      Don't bother asking how I know.

    14. Re:NSA has the ssl keys by Anonymous Coward · · Score: 0

      The MiTM attack is difficult to deploy? you've clearly never used ettercap in your life.

    15. Re:NSA has the ssl keys by dvdkhlng · · Score: 1
      According to wikipedia, "Ettercap is a [..] tool for man-in-the-middle attacks on LAN". It requires you to gain access to a victim's LAN! If the wikipedia page is right, it performs ARP ARP poisoning to redirect vicitm's connections. This can be detected. On a properly administrated network, this attack can automatically be detected, alerting admins etc.

      Requiring access to the LAN and being easily detected for me qualifies as "difficult to deploy". Also note that the computing resources needed to MiTM SSL are pretty enormous (SSL handshake takes a lot of computation). I don't think this will scale to substantial portions of the SSL traffic of a country. Compare that with the almost complete capturing of non-encrypted traffic allegedly implemented by NSA.

  24. who are we fooling? by marienf · · Score: 5, Insightful

    > this means that Firefox on Android with HTTPS Everywhere is now by far the most secure browser
    > against dragnet surveillance attacks like those performed by the NSA, GCHQ, and other intelligence agencies.

    While I certainly think it is a good idea to encrypt traffic, this statement is highly misleading or naive: Since the CA
    system is *flawd by design* and every one of those "authorities" in the long list of built-in CA inside
    your browser can, by negligence or choice, supply any of these and other agencies with a valid certificate for
    *any hostname in the world*, initiatives like these protect your privacy only from your local sysadmin/ISP, and also
    do nothing against traffic analysis.

    Should a US person/company trust that "China Internet Network Information Center" isn't going to create a cert for a
    US bank or company to perform a MITM attach with? Should a Chinese company trust "Wells Fargo" not to?
    Should the Greeks trust "TÜRKTRUST Bilgi letiim ve Biliim Güvenlii Hizmetleri A.. (c) Aralk 2007", or the
    Turks "Hellenic Academic and Research Institutions Cert. Authority"? What on earth makes you think ALL of these
    companies can resists pressures to misbehave? Yet all of them are built-in to your browser and "you" trust them.

    Just go to any (Cloudflare, Akamai..)-accelerated site using https and check out the certificate used to see how that works:
    They are issued certificates for the customer domains they accelerate, and hence have access to all the traffic.
    In essence, they do exactly what a man-in-the-middle attack would do, except on a much grander scale (and with the collusion
    of the actual domain holders). The agencies can carry out such attacks from within the ISP's, and your browser would still show "green".

    The Cert validation in the browsers leads to a *dangerous false sense of security* at most. This is crypto, a weakest-link business
    if ever there was one, folks. It's not ALL, or SOME that need to fail in order for PKI to fail, it's ANY of them.

    Surely, we can do better than that: We should get rid of all centralised security illusions. Why aren't we signing contents using our PGP
    keys that at least make multiple signers possible and habitual, and, and this is the essential difference, IMHO: That *you* have made a
    conscious decision to trust or mistrust, to a certain degree, by reviewing a web of trust, as in informed consent as opposed to blind paternalism
    of massivly built-in, pretrusted certificates by distant companies you really have no clue about.

    WKR,
    -f

    1. Re:who are we fooling? by Anonymous Coward · · Score: 1

      Jesus christ... it was hard enough to go through the process of getting a cert. Now you want me to have to think???

      Reality is people don't care and those who do use Tor. There is a reason I pay in cash for as much stuff as possible in the real world. Sadly in the real world I also buy a lot of stuff online because its cheaper or only available via the web for all practical purposes and most of it via a credit card/paypal. Bitcoins is a bit of an improvement (but not for privacy now, but later), but it's also a setback, in that everything becomes public. But one improvement is that it's decentralized. The potential is zerocoin will be adopted by it or another bitcoin derived currency and we'll have actual privacy from government.

    2. Re:who are we fooling? by dvdkhlng · · Score: 5, Insightful

      > this means that Firefox on Android with HTTPS Everywhere is now by far the most secure browser > against dragnet surveillance attacks like those performed by the NSA, GCHQ, and other intelligence agencies.

      While I certainly think it is a good idea to encrypt traffic, this statement is highly misleading or naive: Since the CA system is *flawd by design* and every one of those "authorities" in the long list of built-in CA inside your browser can, by negligence or choice, supply any of these and other agencies with a valid certificate for *any hostname in the world*, initiatives like these protect your privacy only from your local sysadmin/ISP, and also do nothing against traffic analysis.

      Should a US person/company trust that "China Internet Network Information Center" isn't going to create a cert for a US bank or company to perform a MITM attach with? Should a Chinese company trust "Wells Fargo" not to? Should the Greeks trust "TÜRKTRUST Bilgi letiim ve Biliim Güvenlii Hizmetleri A.. (c) Aralk 2007", or the Turks "Hellenic Academic and Research Institutions Cert. Authority"? What on earth makes you think ALL of these companies can resists pressures to misbehave? Yet all of them are built-in to your browser and "you" trust them.

      [..]

      The Cert validation in the browsers leads to a *dangerous false sense of security* at most. This is crypto, a weakest-link business [..]

      You suggest that MITM attacks on SSL are as bad as someone sniffing on unencrypted traffic. It is not! MITM attacks are active attacks and are much more invasive to carry out. That's not all: in principle all these MITM attacks can be detected: the host key of the Man In The Middle will differ from the host key of the original server (though your browser will accept the differing host key when it is signed by a rogue CA).

      It is pretty dangerous for an adversary to carry out MITM attacks on a large scale, as sooner or later, this is going to be detected. The SSL Everywhere extension for example can (optionally) collect information for and check with the SSL Observatory to detect differing certificates that indicate MITM attacks.

      There's also the Certificate Patrol Firefox Extension that persistently remembers certificates and warns when certificates changed for no apparent reason.

    3. Re:who are we fooling? by Anonymous Coward · · Score: 0

      It is pretty dangerous for an adversary to carry out MITM attacks on a large scale, as sooner or later, this is going to be detected.

      Apparently they weren't detected until the Snowden files showed it is widespread...(hacking into Belgacom for example), and wasn't the FBI requesting the SSL keys of Lavabit to decrypt traffic?

      The SSL Everywhere extension for example can (optionally) collect information for and check with the SSL Observatory to detect differing certificates that indicate MITM attacks.

      a MITM attack would also patch (or redirect) SSL Observatory

      only decentralized with checks on locally stored previously seen certificates can work, otherwise it's just security theater

    4. Re:who are we fooling? by Monoman · · Score: 1

      So what are you proposing instead?

      I think the whole point of HTTPS Everywhere is that using it is better than not using it. Some say the improvement is marginal at best. Some say it isn't an improvement at all. What none of the naysayers are saying is how they are doing it better.

      As security increases, convenience decreases.

      --
      Keep the Classic Slashdot.
    5. Re:who are we fooling? by itsdapead · · Score: 2

      You suggest that MITM attacks on SSL are as bad as someone sniffing on unencrypted traffic. It is not! MITM attacks are active attacks and are much more invasive to carry out.

      Is "false security" better or worse than "no security"? I don't think there's a simple one-size-fits-all answer to that - it depends on the type of threat and who the target is. If the bad guys want to snoop on an individual over a period of time, then traffic sniffing probably is easier. If its an organised gang going after money then MITMing a major ecommerce or banking site might be far more effective - and only needs to be in place for an hour or two to collect enough paydirt.

      Anyway, the headline was "Is Firefox now the most secure mobile browser" not "Is Firefox the most betterer-than-nothing mobile browser". Browsers display nice reassuring padlocks and tell users that "the connection to this website is secure" not "meh, well, its probably safe from casual snooping, but if anybody organised is after you or whoever you're connecting to then you're basically screwed."

      --
      In a survey of 100 programmers, 111111 thought that duck-typing was a good idea.
    6. Re:who are we fooling? by sociocapitalist · · Score: 2

      Why aren't we signing contents using our PGP
      keys that at least make multiple signers possible and habitual, and, and this is the essential difference, IMHO: That *you* have made a
      conscious decision to trust or mistrust, to a certain degree, by reviewing a web of trust, as in informed consent as opposed to blind paternalism
      of massivly built-in, pretrusted certificates by distant companies you really have no clue about.

      I just had this nightmare of facebook offering to spread pgp keys between facebook 'friends'

      Small scale key exchange works but can it really work to communicate on the scale that we use every day? Commercial sites, for example, with all the individual users that connect to them?

      --
      blindly antisocialist = antisocial
    7. Re:who are we fooling? by dvdkhlng · · Score: 2

      It is pretty dangerous for an adversary to carry out MITM attacks on a large scale, as sooner or later, this is going to be detected.

      Apparently they weren't detected until the Snowden files showed it is widespread...(hacking into Belgacom for example), and wasn't the FBI requesting the SSL keys of Lavabit to decrypt traffic?

      The attack the FBI attempted on Lavabit had no relation at all to certificate authorities. They merely requested the private host key of the server to be able to decrypt any recorded SSL traffic for that site. Note how this kind of attack only works when you have access to the server in question (in which case you would be able to directly monitor the plaintext communication anyway by tracing the web server executable). I repeat, this is not related at all to certificate authorities. Also note how this attack does not really scale, as it requires you to actively request and collect SSL host keys (not certs!) of all webservers whose traffic you are interested in. For that reason I would expect that information about your operations *will* inevitably leak to the public. Also web servers in other countries will be relatively well protected against this kind of attack.

      The SSL Everywhere extension for example can (optionally) collect information for and check with the SSL Observatory to detect differing certificates that indicate MITM attacks.

      a MITM attack would also patch (or redirect) SSL Observatory

      only decentralized with checks on locally stored previously seen certificates can work, otherwise it's just security theater

      But here again at MITM attack would be detectable. If the SSL Everywhere guys were not completely stupid they will check the host key of the SSL Observatory against a private certificate authority that they completely own (with the certifcate authorities' key hard-coded into their browser extension). Or more simple, they could just hard-code the public key of the observatory. Or implement certificate pinning etc. etc.

      The only working attack would be for the NSA to MITM every download of the SSL Everywhere executable, patching the certificates contained in its code. But again, this is easy to detect after the fact by inspecting the sources, comparing checksums etc.

      For that reason I'm not afraid at all about MITM, as it does not allow for the broad, secret, non-discriminatory data collection that Snowden's leaks show to be implemented by NSA.

    8. Re:who are we fooling? by dvdkhlng · · Score: 3, Insightful

      You suggest that MITM attacks on SSL are as bad as someone sniffing on unencrypted traffic. It is not! MITM attacks are active attacks and are much more invasive to carry out.

      Is "false security" better or worse than "no security"?

      I really don't understand why everybody tries to reduce these encryption problems on the "false security" vs. "no security" dichotomy. No this is not about false security. This is about security against undetectable passive attackers vs. detectable active attackers. The amount of data a detectable active attacker is able to collect about my person are many orders of magnitude smaller than the amount of data a passive attacker is able to obtain. The active attacker will also only be able to obtain data from the point of time I was chosen as a target. The passive attacker will be able to go back in time and look at my communication (probably many years) before I became interesting enough to be deemed a target.

      This is why implementing SSL, even if no protection at all against MITM existed, is much much better than no SSL at all.

    9. Re:who are we fooling? by jbmartin6 · · Score: 1

      Why do you say the CA system is flawed by design? Do you mean that some agency deliberately introduced the flaws? Or do you just mean that the design is flawed?

      --
      This posting is provided 'AS IS' without warranty of any kind, implied or otherwise.
    10. Re:who are we fooling? by wvmarle · · Score: 1

      The proper way would imho to accept all certificates (no need for those extortion fees, and it allows people to use self-signed certificates), and warn when a certificate changes and the new one is not signed with the original certificate. That's a sign that a MITM has been deployed since you first contacted the site. Even if they successfully get a "trusted" certificate in the name of the site they pretend to be.

      When a MITM is active already on a site on your first visit, you're out of luck. Not much one can do against that.

    11. Re:who are we fooling? by marienf · · Score: 1

      > So what are you proposing instead?
      I'm proposing to stop outsourcing most PKI to central authorities, making the "trust" a conscious user decision.
      Now before you argue that I can remove all authorities from my browser and add exceptions as I go, this is not a solution as what I will find
      is single-signed by some company I have no way of checking. If what I found was multi-signed there would be a reasonable chance of determining
      a level of trust via my web of trust. e.g. I would have something to go on while making that decision.

      > I think the whole point of HTTPS Everywhere is that using it is better than not using it.
      Sure, but HTTPS (SSL, TLS..) is not what I have issues with. What I have issues with is using certificates single-signed by central authorities and preloading these into client software.

      > As security increases, convenience decreases.
      I cannot argue with that :-) I just think it's necessary.

  25. Yeah, third-party scripts send it all anyway by evanh · · Score: 2

    Yes, secure connections are pretty useless if you are being tracked all the time anyway.

  26. You lost me. by Anonymous Coward · · Score: 0

    At "mobile".
    Talk to me again when Desktop is in your vocabulary.

  27. Misleading much... by raist21 · · Score: 3, Insightful

    So what's with the uber pro-Firefox and Android spiel?

    According to the web-site you can get the plug-in for Chrome as well. Albeit beta, but still.
    And if that's the case, you can just install Chrome on your Apple device, it's in the itunes store, and install the plugin for it instead.

    1. Re:Misleading much... by stillpixel · · Score: 2

      Maybe they wanted to start a fanboi flamewar on a tech site for more Ad revenue?

    2. Re:Misleading much... by BZ · · Score: 2

      Assuming the extension works on Chrome on iOS. Which it may not, since that uses a fairly different architecture and rendering engine from Chrome on other platforms...

    3. Re:Misleading much... by Anonymous Coward · · Score: 0

      Although the rendering architecture is different, it uses the same Chromium network stack. I don't think Apple allows Google to support javascript extensions, though.

    4. Re:Misleading much... by Jane+Q.+Public · · Score: 1

      "And if that's the case, you can just install Chrome on your Apple device, it's in the itunes store, and install the plugin for it instead."

      You're missing part of the point. Chrome is intimately intertwined with other Google services, and in fact it's pretty damned hard to keep it separate from those services.

      Government is not the only entity that snoops. And Firefox is the only major browser that doesn't belong to big snoopy corporate interests. (Although Apple SAYS that it doesn't snoop. And lots of people believe them. Certainly it doesn't snoop anything like Google does.)

    5. Re:Misleading much... by TangoMargarine · · Score: 1

      Albeit beta, but still.

      Well duh, it's a Google product. Er, a plugin for a Google product. Whatever.

      --
      Unity? Screw that: XFCE. Slashdot Beta? Screw that: SoylentNews. Australis? Screw that: Pale Moon. UX developers DIAF
  28. Or by Anonymous Coward · · Score: 0

    MyOverpricedUnderpowerdApple.com

    1. Re:Or by stillpixel · · Score: 1

      Man I gotta get me one of those!

  29. mobile device forced to use beta site. Comments un by Anonymous Coward · · Score: 0

    goodbye, slashdot.

  30. Re:mobile device forced to use beta site. Comments by Anonymous Coward · · Score: 0

    bye!

  31. Re:mobile device forced to use beta site. Comments by stillpixel · · Score: 1

    wait don't go! have you tried MyCleanPC.. or maybe a https plugin for your mobile browser?

  32. Re:mobile device forced to use beta site. Comments by Anonymous Coward · · Score: 0

    slashdot doesn't do https

  33. Nah by Greyfox · · Score: 2

    Use iptables to block outgoing requests to any port 80. Then decertify all the certs you don't trust (all of them.) Congratulations! Your web browsing experience is now secure!

    --

    I'm trying to teach myself to set people on fire with my mind... Is it hot in here?

    1. Re:Nah by Anonymous Coward · · Score: 0

      Too bad http still works on ports other than 80. Genius plan thwarted.

    2. Re:Nah by Anonymous Coward · · Score: 0

      what happened to "It just works."

    3. Re:Nah by kasperd · · Score: 1

      Use iptables to block outgoing requests to any port 80.

      Even better, use an iptables level REDIRECT to send the connection to a local http server, and have that http server do an HTTP level redirect to equivalent https URL.

      --

      Do you care about the security of your wireless mouse?
    4. Re:Nah by kasperd · · Score: 1

      Too bad http still works on ports other than 80. Genius plan thwarted.

      Right. Cause users who don't know the difference between http and https and/or are too lazy to type https:/// in the URL are going to be typing a port number manually, when they enter a URL, just such that they can get an insecure connection. And websites, which care enough about security to support https in the first place are going to bring up a plain http server on a non-standard port number, just to ensure that users who don't want security can send all their traffic over a non-standard port - from a device where the user himself decided to block port 80 in the first place for security reasons.

      Being able to run http on other ports has no implication for the security of the proposed setup. Blocking port 80 in order to enforce https is totally sensible, when it is there to protect users, who are not deliberately compromising their own security. An attacker performing a MitM attack cannot force a connection from port 80 onto a different port number, if the connection is blocked before even reaching the Internet.

      --

      Do you care about the security of your wireless mouse?
  34. your move, Apple by globaljustin · · Score: 1

    This is a strong move by the EFF and Mozilla.

    wtf is Apple going to do? promise they will offer the same protection?

    I hate that Firefox can't get on the Apple App Store, and I like Apple products. But this...this is bullshit.

    Will Apple somehow integrate a similar HTTPS into Safari?

    --
    Thank you Dave Raggett
  35. also: mycleanPC by globaljustin · · Score: 1

    seriously if they were trying to troll in order to stifle discussion about this topic, that mycleanPC thing kinda worked...

    reminds me of APK...

    maybe this is a level 2 deployment of the APK chatbot AI

    --
    Thank you Dave Raggett
    1. Re:also: mycleanPC by Anonymous Coward · · Score: 0

      APK's always right though. Nobody ever disproves facts he used.

  36. Re:Apple locked Mozilla Firefox out of their platf by mugurel · · Score: 1

    And no I'm not RMS :(

    no need to stipulate that.

  37. BS.. by SuperDre · · Score: 2

    For this to work, the site must support https, and a lot of sites don't...

    1. Re:BS.. by Anonymous Coward · · Score: 1
    2. Re:BS.. by gmuslera · · Score: 1

      For this to work, the site must have the same content using https. It already checks that the site have an https version to try to use that protocol, the problem happens if the https version is a blank page or have different content.

    3. Re:BS.. by Anonymous Coward · · Score: 0

      Yes, and? If it works with some sites but not with others that is still a huge improvement. Security is not a binary thing, you don't either have complete security or no security. Anyone who thinks like that is going to fail, and anyone who spouts that sort of garbage in public is likely to be someone who is paid to discourage others from actually using more secure software, with the excuse that it is not perfect. Nothing is perfect. Even if your protocols have a security proof and the implementations are flawless, there is still a 1/2^128 chance that someone is simply going to guess the key to your 128 bit symmetric cipher.

  38. Re:Apple locked Mozilla Firefox out of their platf by ZeRu · · Score: 1

    But you might have a reason to reply to a post from a creationist. In this case, parent is just wasting everyone's viewport space.

    --
    If you post as an AC, don't expect me to spend a mod point on you.
  39. It takes two to tango... by Anonymous Coward · · Score: 0

    Requesting sites over HTTPS doesn't do very much if the provider doesn't require Perfect Forward Secrecy. You may request something over SSL, but it is easily discoverable to anyone with a subpoena after-the-fact if it's not PFS.

    See http://en.wikipedia.org/wiki/Perfect_forward_secrecy and http://googleonlinesecurity.blogspot.com/2011/11/protecting-data-for-long-term-with.html for more on why.

    If you want to talk about secure browsers, it's probably worth noting that with PFS, endpoint compromise is the next best strategy for finding out what you are up to. Given that the server is out of your control, that means owning your machine (probably via the browser). Only IE and Chrome use the most modern sandboxing strategies to make exploitation more difficult. This is a little old but still mostly accurate: http://files.accuvant.com/web/files/AccuvantBrowserSecCompar_FINAL.pdf

  40. Re:mobile device forced to use beta site. Comments by noh8rz10 · · Score: 1

    dude you are owning this thread. is the plugin compatible with my HOSTS file?

  41. Centralized Wiretap by Anonymous Coward · · Score: 0

    And now the NSA has a single location to wiretap to gather intelligence on a collection of security concerned and tech savvy users

  42. iPhone by Anonymous Coward · · Score: 0

    Why no https everywhere for FF on iOS?

  43. It's a joke. Laugh. by Ungrounded+Lightning · · Score: 1

    In case you don't get it: It's obviously intended to mimic a fake anti-malware product that spams people with ads for itself.

    Yes, there is a product by that name, which is called out as a "borderline scam" - though mainly with claims that it does little (removing key-only registry entries), may cause trouble, and buying it can result in a periodic charge to your credit card that is difficult to stop.

    --
    Bantam Dominique roosters crow a four-note song. Once you've heard it as "Happy BIRTHday" you can't NOT hear it that way
  44. Of course, like short term memory jokes ... by Ungrounded+Lightning · · Score: 1

    ... it gets boring when repeated too often,

    --
    Bantam Dominique roosters crow a four-note song. Once you've heard it as "Happy BIRTHday" you can't NOT hear it that way
  45. Spamspamspamspam by wonkey_monkey · · Score: 1

    With HTTPS Everywhere, Is Firefox Now the Most Secure Mobile Browser?

    You obviously think it is, so why did you phrase that as a question?

    --
    systemd is Roko's Basilisk.
  46. Monocausality by drolli · · Score: 1

    Supporting https everywhere is *not* a sufficient single reason to be called "the most secure browser".

    Monocausal interpretations of security are the worst enemy of security.

    1. Re:Monocausality by fatphil · · Score: 1

      I'm pretty much sure I entirely agree with you, but I've not heard the term "monocausal" used in this context - do you mean something like "(claiming to be a) silver bullet"?

      --
      Also FatPhil on SoylentNews, id 863
  47. Firefox devs dont care about security by Anonymous Coward · · Score: 0

    Firefox most secure? No! No! No!
    They dont care about security.
    Look at this bug and think again.
    While Chrome can connect to proxy over https, Firefox cant. And wont any soon i guess.

  48. Delusional by Anonymous Coward · · Score: 0

    Anyone who thinks this will prevent dragnet surveillance is fooling themselves.

  49. Not perfect, but it's a start... by bogd · · Score: 4, Insightful

    So basically all this does is to force HTTPS requests instead of HTTP? (took me a while to find out - gotta love the fact that the "clever technology" link on their site, instead of going to a description of the actual technology, goes to... xkcd?! :) )

    I see a few problems with this approach:
    1)Not all content is provided over both HTTP and HTTPS. For multiple reasons, one being performance. Which leads us to the second problem...
    2)A HTTPS session incurs a significant overhead for encryption. Which may be no problem for someone like Google. But for someone hosting his/her own (moderately successful) website on a small server, it might just overload said server.
    3)Quite possibly the biggest problem with HTTPS is the fact that users have been trained over many years to just click "accept/install certificate" on self-signed certs. Not knowing that if you do this you are no longer secure.

    And the more we keep forcing HTTPS, the more webmasters will use self-signed certs. Not many people want to go through the hassle of obtaining (and maintaining!) a valid SSL certificate for every single website they run, even if that cert is free. Which will only exacerbate the problem...

    1. Re:Not perfect, but it's a start... by jdi_knght · · Score: 2

      I see a few problems with this approach: 1)Not all content is provided over both HTTP and HTTPS. For multiple reasons, one being performance. Which leads us to the second problem... 2)A HTTPS session incurs a significant overhead for encryption. Which may be no problem for someone like Google. But for someone hosting his/her own (moderately successful) website on a small server, it might just overload said server. 3)Quite possibly the biggest problem with HTTPS is the fact that users have been trained over many years to just click "accept/install certificate" on self-signed certs. Not knowing that if you do this you are no longer secure. And the more we keep forcing HTTPS, the more webmasters will use self-signed certs. Not many people want to go through the hassle of obtaining (and maintaining!) a valid SSL certificate for every single website they run, even if that cert is free. Which will only exacerbate the problem...

      True, although the effect of #2 is generally pretty low, and because there's the potential for SPDY to pipeline everything over 1 HTTPS connection, total server load caused by each visitor can actually be lower, depending on the web server.

      That said, biggest issues as I see them are:

      1) HTTPS still has the extra overhead of establishing an SSL connection, which makes total page load time longer. The aforementioned SPDY can help compensate for this, but the pipelining of SPDY has the most benefit on sites that are poorly optimized to begin with (lots of resources, don't make use of image sprites, etc). Those who have spent time minimizing their page load time aren't likely to jump on the SSL bandwagon anytime soon.

      2) An SSL certificate is out of reach for most normal people. Sure, you can get one for free from StartSSL, but trying to use the terminal to generate the .crt, install the key on the server, etc isn't for the non-slashdot crowd. Some providers make things a little easier, but there's only so much handholding that can be done. Even where the average person might muddle their way through and figure it out, the average person also uses shared hosting and will probably need to pay to get it installed, because you can't install it yourself on the vast majority of shared hosts - many also don't have SNI enabled and will also require that you use a dedicated IP for the cert which is extra cost there. This is assuming the user didn't find it easiest just to buy a cert via the host at an inflated price.That's a lot of time, work and extra money for the average Joe who is paying $5 to host his WordPress blog and the depth of his expertise is that he just learned how to install plugins.

      3) Client-side MITM has already been happening - I read an article about a school doing it by adding/trusting certs on individual machines and proxying requests through their "fake" server (presumable so they can make sure kids aren't visiting the naughty sites), but can't find the article atm. Not that this is a widespread practise, and just because something isn't bullet-proof doesn't mean you shouldn't use it. But as HTTPS grows in popularity, I wouldn't be at all surprised if we start seeing an increase in malware/toolbars which do something similar.

      I see the 2nd item as the biggest roadblock. And if they want adoption to go up quickly, the only way would be to convince Google to use an SSL cert as one of the factors in the SERPs, since that's the only way to get the majority of webmasters & hosts to make a widespread change insanely fast (and to compete price-wise to do the same for the average Joe). Though to be honest, I don't know that abruptly forcing SSL on everyone would be the greatest idea anyway...

    2. Re:Not perfect, but it's a start... by heypete · · Score: 5, Informative

      I see a few problems with this approach:

      1)Not all content is provided over both HTTP and HTTPS. For multiple reasons, one being performance. Which leads us to the second problem...

      True, which is why HTTPS Everywhere only enables HTTPS on sites that support it (they are specifically whitelisted by the extension devs).

      2)A HTTPS session incurs a significant overhead for encryption. Which may be no problem for someone like Google. But for someone hosting his/her own (moderately successful) website on a small server, it might just overload said server.

      While HTTPS does incur some overhead, it's surprisingly small for modern servers. Google, for example, was able to add SSL/TLS to all Gmail connections with no new hardware, no additional servers, and SSL/TLS accounts for only about 1% of their CPU time (see here for details).

      Pretty much any server will reach other bottlenecks before the slight overhead of SSL/TLS becomes an issue. Using Perfect Forward Secrecy is important for security and using DHE-based ciphers do incur a moderate overhead compared to non-DHE ciphers (a factor of about 3). Using ECDHE instead makes the increase in overhead only about 15% rather than 300%. See here for details.

      3)Quite possibly the biggest problem with HTTPS is the fact that users have been trained over many years to just click "accept/install certificate" on self-signed certs. Not knowing that if you do this you are no longer secure.

      And the more we keep forcing HTTPS, the more webmasters will use self-signed certs. Not many people want to go through the hassle of obtaining (and maintaining!) a valid SSL certificate for every single website they run, even if that cert is free. Which will only exacerbate the problem...

      [citation needed] Getting a domain-validated SSL cert from publicly-available CAs is the work of a few minutes and, as you point out, often available for free or very low cost. Many hosts will automate the generation of a private key and CSR, making the process one of copy-paste for the customer. Other hosts handle the entire process of generating a private key, getting it signed by a CA, and configuring things correctly.

      Sure, some sites use self-signed certs, but these are usually for personal or internal corporate purposes and not for the general public. The scary warnings in browsers aren't likely to go away anytime soon, so I doubt that any webmaster of a website meant for public use is going to be using self-signed certs (other than those catering to specific, tech-savvy audiences).

    3. Re:Not perfect, but it's a start... by Wootery · · Score: 1

      The scary warnings in browsers aren't likely to go away anytime soon, so I doubt that any webmaster of a website meant for public use is going to be using self-signed certs (other than those catering to specific, tech-savvy audiences).

      Tech-savvy audiences are ok with self-signed certs?

    4. Re:Not perfect, but it's a start... by Anonymous Coward · · Score: 0

      Not many people want to go through the hassle of obtaining (and maintaining!) a valid SSL certificate for every single website they run, even if that cert is free. Which will only exacerbate the problem...

      Since when was a self signed certificate not valid? It generates a scary warning but it's certainly a valid cert.
      I would much rather my bank sent me a copy of their CA cert with the other paperwork when I opened an account to install into my browser, and have it throw up a scary warning if the connection WASN'T signed with that key.

    5. Re:Not perfect, but it's a start... by heypete · · Score: 1

      The scary warnings in browsers aren't likely to go away anytime soon, so I doubt that any webmaster of a website meant for public use is going to be using self-signed certs (other than those catering to specific, tech-savvy audiences).

      Tech-savvy audiences are ok with self-signed certs?

      Some, sure.

      Note how I used "specific". That word was used for a reason.

      There may be, for example, a community of crypto-savvy users who would rather not rely on a third-party CA to authenticate their certs. A site administrator could issue a self-signed certificate for the community site and post the PGP-signed details (e.g. fingerprint, key length, etc.) of the certificate so that members could verify its authenticity.

      Other sites, like the anti-spam DNSBL named SORBS, use certs issued by their own internal CA. Users of that site may well trust the CA to issue such certs.

      Self-signed certs have their uses, but are not really suitable for secure sites intended to be used by the general public.

    6. Re:Not perfect, but it's a start... by petermgreen · · Score: 1

      Getting a domain-validated SSL cert from publicly-available CAs is the work of a few minutes and, as you point out, often available for free or very low cost.

      That is true, however.

      1: until internet explorer on windows XP and the default browser on android 2.x die out we can only use one cert per IP. So we are stuck with either managing seperate IPs for each hostname or paying significantly more to have multiple names on one cert.;
      2: you have to go through the certificate dance again every year or two. If you don't then your users start getting warnings.

      --
      note: i'm known as plugwash most places but i screwd up registering that here somehow in the past and now can't register
    7. Re:Not perfect, but it's a start... by Wootery · · Score: 1

      Sounds reasonable - I thought you meant you were expecting tech-savvy users to ignore browser warnings.

    8. Re:Not perfect, but it's a start... by tepples · · Score: 1

      until internet explorer on windows XP and the default browser on android 2.x die out we can only use one cert per IP.

      Sixty-two more days until Windows XP support ends and IE/XP can be presumed vulnerable to forever-days.

      you have to go through the certificate dance again every year or two. If you don't then your users start getting warnings.

      You have to go through the hosting renewal dance and domain renewal dance anyway.

    9. Re:Not perfect, but it's a start... by ObsessiveMathsFreak · · Score: 1

      3)Quite possibly the biggest problem with HTTPS is the fact that users have been trained over many years to just click "accept/install certificate" on self-signed certs. Not knowing that if you do this you are no longer secure.

      Wrong. Wrong. Wrong. Get your head out of Applied Cryptography and come into the real world.

      Accepting a self signed cert means your connection is far more secure than an unencrypted one. Oh there could be a myth in the middle attack, but in that even a CA verified cert is only secure by one more party. Let me put it in a table

      CA cert: 2 parties (In theory)
      Self-signed cert: 2-3 parties (1 hijacker in theory)
      Unencrypted connection: 2-n parties (where n is the total number of people with access to plaintext traffic across all networks the message is transmitted through.)

      Do I even need to add how much traffic is being transmitted wirelessly nowadays? Do I?

      Let me ask you directly: Do you believe that a person trusting a self-signed cert is less secure than a person using an unencrypted connection? Honestly? Don't try to redefine security to mean encryption+trust; not now, not after the NSA mass surveillance revelations. Just don't.

      Just tell me who is more secure: Aunt Tillie sending all her emails over unencrypted connections, or Dave sending his emails to a server with a self-signed cert? Who is more secure?

      --
      May the Maths Be with you!
    10. Re:Not perfect, but it's a start... by bogd · · Score: 1
      I will grant you the fact that unencrypted connections are vulnerable to both sniffing and MITM, while self-signed certs are "only" vulnerable to MITM. But you seem to believe that there is a huge leap from sniffing to mounting a MITM - and this is where we disagree. While MITM may incur an additional cost for the attacker, it is far from being an unrealistic scenario (see below for some examples).

      As for the rest of your rant^H^H^H^H post, it doesn't really make sense. You believe that a self-signed certificate will somehow "protect" you from the NSA? Who is somehow incapable of a MITM? Well, this, this and this may prove... enlightening. And while we're on the topic of "additional reading", may I also recommend "Alice in Warningland" - a study showing 70+% clickthrough rates for SSL warnings.

      There are some other issues, like you mentioning wireless traffic. With WPA2 being the default, and with many modern wireless NICs no longer supporting promiscuous mode, it is often more difficult to sniff wireless traffic than to mount a MITM on a wired network (especially when the target is the victim's router - again, see the links above).

      Security means encryption + integrity + authentication. Period. Anything less is no longer secure.

    11. Re:Not perfect, but it's a start... by bogd · · Score: 1
      I forgot to answer your question...

      Let me ask you directly: Do you believe that a person trusting a self-signed cert is less secure than a person using an unencrypted connection?

      No. I never said that it is less secure. I said that once you start blindly accepting self-signed SSL certificates, you are no longer secure. Maybe not as insecure as with clear text, but definitely not too far away from it.

    12. Re:Not perfect, but it's a start... by ObsessiveMathsFreak · · Score: 1

      Security means encryption + integrity + authentication. Period. Anything less is no longer secure.

      Why? Why should this be the standard for "security"?

      How are we to certify encryption, integrity, or authentication? Through certification authorities? Or trusting organisations like NIST? Are we to hope that our data will have integrity anywhere in an internet which is dystopianly dominated by agencies like the NSA?

      Your standards are arbitrary, and ultimately flawed. Dogmatic adherence to them has lead Mozilla at least to all but blacklist general purpose basic encryption (sans "security") on the web, and has lead to a world where all data is up for grabs by default, and which in fact has been so grabbed.

      Firefox should not be making decisions for users on whether or not authentication less encryption is a good or bad thing. Just don't highlight self signed certs with a yellow lock bar was all anyone could want. But Mozilla went beyond this and the encrypted web has been set back by a decade or more.

      P.S.
      (I increasingly believe that Mozilla's decision, and quite possibly the encryption communities dogmatic insistence on authentication were in part motivated by the NSAs soft influence. /notobviouslyparanoidanymoretinfoil)

      --
      May the Maths Be with you!
    13. Re:Not perfect, but it's a start... by petermgreen · · Score: 1

      Sixty-two more days until Windows XP support ends and IE/XP can be presumed vulnerable to forever-days.

      Yeah :(

      Unfortunately i'm not sure that will stop people using it.

      You have to go through the hosting renewal dance and domain renewal dance anyway.

      At least with the providers I use hosting is just on an ongoing contract automatically paid.

      With domain renewals I can either put them on automatic renewal or renew at my conviniance for pretty much as long as I want and with no penalties for renewing early.

      With SSL certs I have to do a manual dance* every time it comes up for renewal (which seems to be once a year for the only free provider i'm aware of) and do that dance within an annoyingly short time window.

      * Revalidate myself with the ssl provider, generate the csr, feed the csr to the provider (who ignore most of it), get the cert, search for the correct intermediate certs to go with it and install it into the web server. Along the way of course I have to look up how to do many of the steps again because it's long enough since I last did them that I forget the details.

      --
      note: i'm known as plugwash most places but i screwd up registering that here somehow in the past and now can't register
    14. Re:Not perfect, but it's a start... by bogd · · Score: 1

      Security means encryption + integrity + authentication.

      Why? Why should this be the standard for "security"?

      Because so far it's the best we have. And because security is only as strong as the weakest link.
      You seem, however, to disagree. What would, in your opinion, be a reasonable standard for end-to-end security?

      I'm not sure what you mean by Mozilla "blacklisting" basic encryption. As far as I know, self-signed certs work just fine in Mozilla. With a warning, of course - as it should be (and IMHO, that warning should be much stronger than it already is).

      Just don't highlight self signed certs with a yellow lock bar was all anyone could want

      You seem to forget that the web is not only visited by people like you, me, and most of the /. crew. Average Joe doesn't know how to look at the lock bar, and he doesn't know how to check if a certificate is valid. And this makes him the point where encryption without trust falls apart.

      And since you seem intent on throwing NSA around - while it may be easier for them to just sniff traffic, they really have no problem in mounting a MITM attack (see links in my previous post). And while it has not been proven yet, they might just as well have the ability to generate their own certificates, trusted by the major browser vendors (see here - but again, keep in mind that this is just speculation at the moment).

      So even if we have encryption+authentication, it still may not be enough. Not when faced with an attacker which has the resources to break the chain of trust.

      I won't even get started on the fact that the NSA has knowingly attempted to compromise encryption standards. :)

  50. Re:Apple locked Mozilla Firefox out of their platf by Cenan · · Score: 0

    Everybody knows RMS doesn't have a phone, he's still trying to assemble his first from open hardware made by happy fairies from StallmanLand(TM).

    --
    ... whatever ...
  51. Now on the RFP: 5yr warranty and lifetime firmware by Anonymous Coward · · Score: 0

    Well, We do government purchase contracrts where I work. We tend to buy 100+ of anything (including HP DL servers) an year, and unlike standard "buy and get screwed" deals, governments buy through a services contract.

    Guess what I just added to our standard boilerplate? We already required unlimited 5yr warranty for everything inside the chassis (yes, including HDDs, SSDs and RAID batteries). Now we also require unlimited, lifetime firmware updates. lifetime we define as "from the time of purchase until a minimum of 5yr after the product has been declared in end-of-life status by the vendor".

    If HP doesnt want to sell it that way anymore, we will just buy Lenovo or Dell. Supermicro is out because their firmware team is a two-man operation or something which is still doing things as they were in '80s.

  52. Re:Breaks some websites (1) by Anonymous Coward · · Score: 0

    Well, I have a Mac too. I'd like to know when this "Apple has locked Mozilla Firefox out of their platforms" shit happened, because I was using Mozilla Firefox at home just last night and I went to bed around midnight...

    I might have understood if the had said something along the lines of "locked FF out of [some/one] of their platforms" ...or is this yet another reason why I shouldn't "upgrade" to Mavericks??

  53. I guess your guesswork is faulty by Anonymous Coward · · Score: 0

    Work on that bug depends on bug 715905 being patched first. It is already ASSIGNED and if you have ChatZilla you can pester mayhemer about it with the following command:
    /at ircs://irc.mozilla.org:6697/mayhemer,isnick?msg=Please%20hurry%20up%20and%20patch%20bug%20715905%20so%20work%20on%20bug%20378637%20can%20proceed

  54. Re:Breaks some websites (1) by Anonymous Coward · · Score: 0

    The article is only talking about mobile, and "Mavericks" isn't what Apple have called their mobile platform on iOS. I mean seriously, why would you pick on an added "s" in the summary by incorrectly abbreviating Firefox as "FF" instead of "Fx"?

  55. what's secure about this ? by dan_in_dublin · · Score: 1

    This is stupid, there's no benefit to using https on many sites. We can understand a security need by thinking about confidentiality, integrity, and availability. If I connect with https to a site which doesnt have my personal data (e.g. news sites) there is no benefit to confidentiality - the site is availabile to anyone, the info isnt confidential to me. Integrity - without 2 way authentication (which https typically doesnt do) there is only a marginal increase in difficult to compromise the integrity of a http request or response. Why would anyone do that with something like news though. Availability https doesnt change anything, probably makes it worse as the site has to negotiate TLS sessions Accessing sites with personal data, banks, email, faceboook - https is essential. Accessing sites without personal info, such as news, https accomplishes strictly nothing, it's is a waste of cpu cycles and the energy that powers them

  56. Sounds like a good idea, but a big pain by Anonymous Coward · · Score: 0

    HTTPS Everywhere sounds good, but many web sites aren't set up properly and break badly. Using this extension on a mobile device would be a royal pain, trying to add exceptions and fix breakage without a normal browser.

    I see a lot of sites which don't implement CSS properly over HTTPS, so their pages look like a disaster because the CSS doesn't load properly. It's like they never test their web sites on anything but default IE installs. Lowest bidder!

  57. firefox jumping the shark? by csumpi · · Score: 1

    is this publicity stunt a sign of some trouble at firefox? otherwise they should be smarter than making stupid claims like this, right?

    1. Re:firefox jumping the shark? by Anonymous Coward · · Score: 1

      This is the EFF saying that a product made by the EFF is good at doing what it is designed to do. It just so happens that the product happens to be a Firefox addon and is designed to make Firefox browsers more secure. The EFF is saying that their product makes Firefox for Android more resilient against surveillance than other mobile browsers. Mozilla isn't involved in the article.

  58. duh by smash · · Score: 1

    where is the HTTPS terminated and who holds the keys?

    --
    I run: Windows, OS X, Linux, FreeBSD. Just because you have a hammer, doesn't mean everything is a nail.
  59. I hate to say this, but... by Anonymous Coward · · Score: 0

    This does not stop the feds.
    They simply go to the isp, hand them an nsl, and have them pipe all traffic into/out of a vpn/ssl anonymizer service through their blackbox, and then follow it to the destination.

    You watch all the traffic to somedescent.org, correlated back to the vpn/ssl provider, and using your box in the middle can unmask whoever you want.

    Your welcome.
    Sincerely,
    A former ISP syseng

  60. slowing spooks down by Anonymous Coward · · Score: 0

    The NSA likely has keys from all the major SSL cert vendors [...]

    The more we can prevent wholesale collection and analysis the better. Even if the spooks had the private keys, it would still mean they have to spend time/energy decrypting they've just snapped up. This is still worth something, especially relative to them just snapping it up and being able to work on it right away.

    Even if they had the private keys, using ECDH and DHE means that they have to spoof and interact with client/s directly.

    The more speed bumps we can put in before the analysis process, the more the spooks will have to start focusing on individuals and leave the public-at-large alone.

  61. Unfortunately? by Anonymous Coward · · Score: 0

    Noooooooo. This is a wonderful opportunity for iOS sufferers to switch to the Android experience they've been craving. Bonus: Now they have no excuse not to throw their Apple device into a busy roadway and enjoy watching it be ground into dust by 18-wheelers! Win-win-win.

  62. just want to say thank you by onepoint · · Score: 1

    Just want to say thank you

    --
    if you see me, smile and say hello.
  63. Re:Breaks some websites (Java 7u51) by markdowling · · Score: 1

    You need to add them to the Java Control Panel applet exception list. Works for me.

  64. Why doesn't Slashdot do SSL? by crow · · Score: 3, Interesting

    This doesn't work with Slashdot. At least if you put in a https, it redirects, so they have it set up; they just don't use it. You would think that a technology site would be up on current technology.

  65. The presumption is... by QuietLagoon · · Score: 2
    ... that HTTPS is itself secure.

    .
    It is not.

  66. Re:It's a joke. Laugh. by ImprovOmega · · Score: 2

    It's actually wrapped back around to advertising. See, they're just trying to camouflage it as "humorous" to get one or two people to think it's funny, haha, cute joke while getting their name out there. The problem is that it's still just advertising. It just requires an extra layer of cynicism to see it for what it is.

  67. Hipsterism of a slightly different flavor tastes by TangoMargarine · · Score: 1

    as sweet

    Or the people who feel the need to start a new comment thread talking about people talking about spamming...

    Crap. Now I'm talking about people talking about people talking about spamming.

    --
    Unity? Screw that: XFCE. Slashdot Beta? Screw that: SoylentNews. Australis? Screw that: Pale Moon. UX developers DIAF
  68. Betteridges Law of Headlines finally proven wrong? by allo · · Score: 1

    Betteridges Law of Headlines finally proven wrong?

  69. Re:Hipsterism of a slightly different flavor taste by stillpixel · · Score: 1

    Talking about people talking about people talking about people spamming is so 6 comments ago.

  70. He's been here before by Anonymous Coward · · Score: 0

    That spam is recycled from a few years back, he stopped when folks started making him look too stupid for even him. I wish someone would bitchslap him, and while you're bitchslapping people, bitchslap whoever made this beta bullshit that won't let you log in or change the threshold above -1.

    Journaling about it this evening. Why is Dice trying to kill slashdot?

  71. Damn Beta site by Algae_94 · · Score: 1

    It looks like I can filter the Beta site comments by ranking, but there is then no way to read a parent comment if it doesn't make the cut. This gives me the choice of, read all this CleanPC shit, or not be able to read the low ranked parent of any highly ranked post.

    It also appears that the post anonymous feature is gone. Now I'm going to have to completely log out to do that. I'm not impressed with this.

  72. Most Secure Completely Secure. Know the diff. by Anonymous Coward · · Score: 0

    Too many are interpreting "most secure" as "completely secure." Try dispproving Firefox w/HTTPS everywhere as most secure rather than arguing away it as completely secure.

  73. I moved pineight.com to WebFaction for SNI by tepples · · Score: 1

    you can't install it yourself on the vast majority of shared hosts - many also don't have SNI enabled and will also require that you use a dedicated IP for the cert which is extra cost there.

    SNI support is part of why I switched pineight.com from Go Daddy shared hosting to WebFaction shared hosting. But I think shared hosts don't offer SNI hosting because of the perceived support cost of complaints from users of Internet Explorer for Windows XP. It and Android Browser for Android 2.x are the last two remaining major browsers that don't support SNI. But in two months, Microsoft will stop releasing security updates for Windows XP. At that point, migrating to SNI will make sense because server operators can presume that IE/XP is insecure, especially once computer vandals start deploying client-side MITM through a forever-day exploit in Windows XP. The login form summarizes the Firesheep, SNI, and IE/XP issues and links to a TLS version of the form for users with compatible browsers.

  74. WTF by Anonymous Coward · · Score: 0

    Why do people trust HTTPS? If you are using a company computer or phone it's likely that your machine is already compromised. Our corporate IT has a self-signed CA certificate that they drop on every machine and then issue spoof certificates for any HTTPS site you visit so they can MITM your SSL session. Unless you really know how SSL works, you'd be none the wiser.

  75. So tell me.... by Anonymous Coward · · Score: 0

    I have a website that uses static text so I have no php, perl, databases, etc. if you visit it with forced HTTPS that means that my site will work or my humble server plan will suffer for something that I cannot deliver?

  76. If enough sites put up a safety warning by tepples · · Score: 1
    You make a good point about the labor difference between renewing a domain and hosting and renewing a certificate.

    Unfortunately i'm not sure that [end of support] will stop people using [Windows XP].

    They will likely stop once enough popular web sites start informing them about the end of support and its ramifications. The message for old IE would look like this, including a subtle dig at the Copyright Term Extension Act:

    To protect the safety of your account, $site_name requires everyone to log in through a secure connection. This means we cannot allow logging in from web browsers that no longer get security updates. Microsoft stopped providing security updates for Internet Explorer on Windows XP in April 2014, and updates are not scheduled to resume until January 2097. Ask your system administrator or local PC builder about upgrading.

    And the message for old Android Browser would look like this:

    To protect the safety of your account, $site_name requires everyone to log in through a secure connection. This means we cannot allow logging in from web browsers that no longer get security updates. Ask your device manufacturer about an upgrade to Android 4, or install the Mozilla Firefox browser through Google Play Store.

  77. I used soap and water, by Anonymous Coward · · Score: 0

    I used soap and water to clean my PC of viruses. I had a bit of problem with the mouse and keyboard, because of the layers of dirt from years of fingering the keys, while drinking coffee with the other hand, or eating a "fresh donut".
    The mouse was easier, just a problem with the wheel. It too was caked with old icing.

    Now my pc works like new. The fins on the cooling heatsinks have no lint, the DVD reader works like new.

    And after the equipment dried up, all was well. Ohh, I forgot to mention, I use a VM and Linux.

  78. Why doesn't the beta site auto-populate comment su by NoImNotNineVolt · · Score: 1

    That's GNU/Hurt-Mobile OS. Have you heard a single word RMS has said?!

    --
    Chuuch. Preach. Tabernacle.
  79. request policy by Anonymous Coward · · Score: 0

    I think RequestPolicy is more important for security than https-everywhere.

  80. Fix NoScript by Anonymous Coward · · Score: 0

    Unfortunately, the mobile version of NoScript makes page loading extremely buggy and slow, at least in my experience. Once it gets fixed, Firefox for Android + Self Destructing Cookies + HTTPS Everywhere + NoScript + ProxyMobile = best, most secure Android browser.