Google Chrome Wants To Block Some HTTP File Downloads (zdnet.com)
An anonymous reader writes: Google wants to block some file downloads carried out via HTTP on websites that use HTTPS. The plan is to block EXE, DMG, CRX, ZIP, GZIP, BZIP, TAR, RAR, and 7Z file downloads when the download is initiated via HTTP but the website URL shows HTTPS.
Google said it's currently not thinking of blocking all downloads started from HTTP sites, since the browser already warns users about a site's poor security via the "Not Secure" indicator in the URL bar. The idea is to block insecure downloads on sites that appear to be secure (loaded via HTTPS) but where the downloads take place via plain ol' HTTP.
Google said it's currently not thinking of blocking all downloads started from HTTP sites, since the browser already warns users about a site's poor security via the "Not Secure" indicator in the URL bar. The idea is to block insecure downloads on sites that appear to be secure (loaded via HTTPS) but where the downloads take place via plain ol' HTTP.
Why oh why does Google think that they know better than everyone? Give a warning, sure, and then let the user decide. Just the same way it handles an HTTP page vs an HTTPS page.
Punishing sites for using mixed content? That's a paddlin'.
Google is making there own version of the web. I think Microsoft tried to do this and failed.
But http or https doesn't really matter these days, even malicious sites are using https..
As long as you get a warning when downloading and you are still able to download the file, I don't have anything against it. But if they just block download completely because it isn't coming from an https site, than I won't be using Chrome anymore.. As I said, https doesn't say anything about the file being safe.
Have you not yet learned from experience? I enjoy poking at you. It's entertaining to me.
Can someone confirm how they are planning to detect these file types to disallow downloading? Are they going purely by extension or are they testing for mimetypes?
I only ask because as a developer I hate when filetypes are assumed just purely based on extension. Not only that but, is this going out on all OSes? Because .exe files are harmless on Linux (unless transmitted again), for example.
Ok, and how exactly do they expect people to be able to download software, or other files?
Apparently in Google's world everyone has gigabit fibre so very large log files (for example) is not an issue. But for those of us in the real world, being able to compress stuff before sending is still incredibly valuable.
(And for anyone that plans to latch onto the log file example like starving dog on a steak and say "Well you should be splitting up your log files!", I kindly invite you to eff off in advance. I'm talking about the real world, where shit happens on a routine basis...)
I'm confused. D'you have a stalker troll?
I was making a point about having things shoved down one's throat. Like what Google likes to do.
Is that we could all agree on some sort of standard whereby from a secure site you could initiate a download, have that download be unencrypted, but the download link would include a sha256 checksum that would be checked automatically by the browser once the download was complete.
This would allow popular downloads to be cached closer to the user, while providing for verification of the download integrity.
...si hoc legere nimium eruditionis habes...
Most sites provide their file hashes over HTTPS. If I'm going to verify the file on my end anyway, there's no real reason for the site to waste CPU encrypting the entire ISO every time someone downloads it.
Digital signatures and hash verification address the same security concerns with less impact.
---
According to the latest ruleset, this post should be modded as Vorpal Flamebait +5.
You can still download the .exe over HTTPS and run it when it's done downloading.
Why exactly ban these file types' transmission over HTTP again? It has nothing to do with encryption.
Good thing I don't use that dog shit Chrome though.
Let me guess: So that a site without a Hollywood approved security certificate can't make use of HTTPS to encrypt and circumvent mandatory Hollywood file inspection?
Have gnu, will travel.
I might have a stalker troll. I've been poking at them a lot the last few days. The entertainment helps me get through my work day.
But, now that I can put your response into its proper context, well done. Read the right way, it did give me a chuckle.
It brings back bad memories of when Google decided that certain filetypes were too dangerous to be handled by gmail, so suddenly I could no longer access a bunch of .js files a buddy had sent me long ago that I had in my mailbox. I was not impressed.
Considering how many are downloading from wifi or untrusted router, it doesn't make sense to use http because you can get you file change during the download. HTTPS wont slow you down and will offer basic security against the hacker next door. For web hosting, https://letsencrypt.org/ offer free SSL certificates.
Including .EXE but forgetting about .SCR, .COM, .BAT, .LNK, and possibly other extensions that are treated just like .EXE files?
(Yes, .BAT files which are valid PE executables will run as executables, and it won't try to execute it as a command prompt script)
Welcome to slashdot. Where everyone has a stalker troll. It's called freedom and being an AC.
I think there's actually a push to encrypt too much. It's got obvious benefits for privacy and security, but encrypted traffic can't use the internet's caching infrastructure which would benefit popular downloads, which tend to be ZIPs, EXEs, TARs and such. What I'd really like to see is browser integration to insecurely download files and securely confirm its fingerprint.
That said, informing the user aware of an unencrypted download from an encrypted site would be good. Blocking it would be bad.
Google Chrome...the Windows 10 Spy/Virus of web browsers!
They're welcome to it! When I tire of the entertainment I get from poking at them, I'll stop poking at them ;)
... web site to go through all their web pages and make sure that no instances of "http:" are accidentally left in pages where downloads are available?
It might be easier for web sites to merely add a browser detector to their pages to warn the user that they're using a product from a vendor that's actively trying to make their use of the Internet into a royal pain in the behind?
CUR ALLOC 20195.....5804M
The S in HTTPS does not have anything to do with SECURITY it means SSL. It means, and only mean, and has no meaning any more than, that the connection between you and whomever you are talking too (which may or may not be who you think it is) is encrypted (PRIVACY mode is engaged) so that third-parties in betwixt cannot make sense of the data transmitted (nor easily make undetected alterations to that data).
Repeat again with feeling: HTTPS HAS NOTHING WHATSOEVER TO DO WITH SECURITY. HTTPS DOES NOT IMPLY THAT SOMETHING IS SECURE. NOT HAVING HTTPS DOES NOT IMPLY SOMETHING IS NOT SECURE. HTTPS HAS NOTHING WHATSOEVER TO DO WITH SECURITY.
Why on earth would one want to protect a file download against third parties? There are far better and more efficient ways to do it that HTTPS which again, has nothing whatever to do with SECURITY and whether or not the file is malicious, but is only a transport PRIVACY measure against third-parties interposed between the two end-points (who may not be who you think they are).
The Google Chrome engineer who posted this ask to the W3C mailing list ( https://lists.w3.org/Archives/... ) also made a social media poll, https://twitter.com/estark37/s...
Essentially, they're reinforcing their own echo-chamber effect to only listen to confirmations of their conceived notion of correctness rather than truly encouraging discourse on the matter. Her poll options are, "yes" and "yes" -- and several Twitter replies have been deleted.
Personally, it seems they are an engineer looking for a problem to solve to help justify their job... and that's just sad in itself.
Fuck google.
Between Microsoft shoving things up your ass and Google shoving things down your throat, I think you are well covered.
It's getting close to a point where we need to make our own web and web browsers, with blackjack and hookers (but seriously!). There are lots of free TCP ports left, let's just choose another one and walk away from the HTTP2/3/AMP/QUIC bullsh$t. Make a translator gateway if someone wants to visit the "Google-web" with all of its limitations.
This is a clear violation of stack layers -- a general purpose APP for browsing and fetching online content should NOT attempt to be the gatekeeper for what the TRANSPORT is trying to send. This is equivalent to an email program refusing to forward mails with the (non)-word 'alot' in it, because the programmers want to stamp out bad grammar. It's NOT THE PROGRAM'S PLACE TO DECIDE.
Can Google please block this shit!
Truth and fact you jews supplied from your own doings, history, book of law you don't want exposed to the goyim non-jew cattle bother you jew?
they're using file extensions in 2019 and not mime types? this is the real google, the big billion-dollar technology company? is this an old Apr 1 article? does google not think someone might possibly use a different extension and let the computer run the file by mime type? do computers really use extensions now? is this windows-only? so many questions
(this reminds me of all those INVOICE.DOC.JPG.ZIP.EXE.RAR files in e-mails for some reason)
It already blocks .torrent files on certain sites. Says they are dangerous. Orly?
this makes it harder for their competitors to index the files in their search engines. I forget the specific technical details, but google's push for HTTPS has nothing to do with privacy and security (I mean, look at who we're talking about here, it's a company that exits to sell ads and your demographic data).
If anyone remembers the technical details feel free to chime in, but this is just an anti-competitive trick.
Hi! I make Firefox Plug-ins. Check 'em out @ https://addons.mozilla.org/en-US/firefox/addon/youtube-mp3-podcaster/
If there was a virus that would render 4chan's foul spawn unable to get on the Internet, I'd be all for it. Even if you're joking, you're still a disgusting piece of crap.
The world's burning. Moped Jesus spotted on I50. Details at 11.
What a bunch of nanny state bullshit!
Harrison's Postulate - "For every action there is an equal and opposite criticism"
No seriously though, what the fuck?
As for the change, they already have the infrastructure baked into Chrome and firefox. I have gone through the code of both Chrome and Firefox as part of an audit. The control Google has over everything we do online is ... terrifying. I'd take a devil I can see over one who lives in California.
Yeah, if you ask 10 random people what TLS is, you'll find out why Google security engineers think that they know security better than thr average consumer does. It's their. JOB to know security, so they SHOULD be much better informed than the average user. They shouldn't forget that fact when they make *defaults* and *warnings*.
On the other hand, I've been an internet security professional for twenty years. I can reasonably decide to override the defaults in selected situations. I am not a typical user in that regard.
don't use their browser. easy.
On the contrary, i have some recollection of some nation-states poisioning downloads of "encrypted" communication apps to be able to eavesdrop. (Egypt? Iran?).
If you had a physical safe, 2,000 pounds, which would open whenever someone tapped it on the left side, that would be a defective product. Since you probably bought the safe to protect valuables, you'd want to know if it doesn't offer any security. A security warning about that safe would be warranted.
A cardboard box would not be defective of it could be opened easily. You don't store gold in a cardboard box and expect high security.
By applying TLS, the site operators are essentially declaring that the content needs to be protected and claiming that it is protected. If it's not actually protected as claimed, users may want to know about that.
I can't use chrome to browse torrents because it has a problem downloading magnet links. I feel like Firefox is becoming the better option by the day.
Khazar Talmudic Jews believe this of all they call goyim/gentiles (any non-jew): Jews = biggest racists of all for which they "jew guilt" you for no less! They're hypocrites known as thieves all thru history or were Argentines in the 1940 under Peron, Spanish inquistion, France (1306), Egypt (despoiled/robbed by jews), Arabs (pre & post 1948), England (1330 Edward longshanks), Romans under titus, Russia pogroms and Germany who got rid of them from their nations nazi german's too? No. Driven into DESERTS ages ago! Don't wonder why after all those exilings above.
Should anyone doubt any of this see Jacob Javits' crony Rosenthal spill the beans on it https://www.youtube.com/watch?v=D4zMVZ8HnFI/ where he called all Christianity fools for helping Israel and the biggest scam of all time per their beliefs below from their Talmud.
This is the province of the synagogue of Satan (Pharisees whom Jesus Christ himself kicked to the curb out of the temple & they killed him for it. Jeremiah did the same to them also + the Essenes could not stand them either breaking away from the pharisee corruption):
Mark Zuckerberg stole the Winklevoss twins' code for Fakebook (figures as he is a thieving low jew too).
Maria Abramovic satanist spirit cooker pal of Hillary Clinton the Voodoo queen is a jew https://www.google.com/search?...
Like Hillary Clinton's mentor Saul Alinsky author of rules for radicals book dedicated to Lucifer
"Most Jews do not like to admit it, but our god is Lucifer Â- so I wasnÂ't lying Â- and we are his chosen people. Lucifer is very much aliveÂ" Harold Rosenthal http://www.thetruthseeker.co.u...
Jewish rabbi openly admits to satan worship use white children's blood they kill for passover bread, infiltrating and subverting the catholic church, creating the Jesuit order https://www.youtube.com/watch?... and https://www.youtube.com/watch?...
Barbara Spectre, a jew, tells everyone it's jews orchestrating the muslim migrant problem in Europe https://www.youtube.com/watch?v=MFE0qAiofMQ/ . No migrant raping of women in Poland. Tons in Sweden. Do the math. Use common-sense. This is to get muslims and other goyim/gentiles to wipe one another out as incompatible cultures that will clash and always have.
Rabbi A. Finkelstein ADMITS their greatest enemies are ARABS and WHITES (blacks too) whom they wish to kill one another in a 'theater of war' which they find AMUSING https://www.youtube.com/watch?...
Finkelstein also admits JEWS DID 9/11 (perpetrated by the Mossad & Bebe Netanyahu of ISRAEL) https://www.youtube.com/watch?... profiting by it (and that 3,000 jews employed there did not show up for work that day knowing about it beforehand).
Finkelstein also admits JEWS are going to destroy the U.S. Dollar and dumping it for other world currencies and gold to destroy the United States.
George Soros who funds groups to create division in the USA?? A jew. One who sold his own jew people into death for the nazis.
Zucker now FIRED @ CNN is another frying publicly for lying about "russians" and John Bonifield a producer @ CNN said it is bs. Van Jones did also.
Bernie Madoff (who made off with everyone's money, especially construction union pensions) shows the thieving nature of the JUDEN!
Michael Milken (another JEW SCAMMER junk bondsman THIEF)
Ivan Boesky
The problem is that you suggest the common user can tell the difference between a cardboard box and a safe. They can't (thus the green locks and such), and yet we're still treating a safe with potentially no lock (or potentially the best lock of all, if you roll your own cert, verify keys out-of-band, and save them) as a less secure container than a cardboard box. Which it in no way is.
"When information is power, privacy is freedom" - Jah-Wren Ryel
Khazar Talmudic Jews believe this of all they call goyim/gentiles (any non-jew): Jews = biggest racists of all for which they "jew guilt" you for no less! They're hypocrites known as thieves all thru history or were Argentines in the 1940 under Peron, Spanish inquistion, France (1306), Egypt (despoiled/robbed by jews), Arabs (pre & post 1948), England (1330 Edward longshanks), Romans under titus, Russia pogroms and Germany who got rid of them from their nations nazi german's too? No. Driven into DESERTS ages ago! Don't wonder why after all those exilings above.
Should anyone doubt any of this see Jacob Javits' crony Rosenthal spill the beans on it https://www.youtube.com/watch?v=D4zMVZ8HnFI/ where he called all Christianity fools for helping Israel and the biggest scam of all time per their beliefs below from their Talmud.
This is the province of the synagogue of Satan (Pharisees whom Jesus Christ himself kicked to the curb out of the temple & they killed him for it. Jeremiah did the same to them also + the Essenes could not stand them either breaking away from the pharisee corruption):
Mark Zuckerberg stole the Winklevoss twins' code for Fakebook (figures as he is a thieving low jew too).
Maria Abramovic satanist spirit cooker pal of Hillary Clinton the Voodoo queen is a jew https://www.google.com/search?...
Like Hillary Clinton's mentor Saul Alinsky author of rules for radicals book dedicated to Lucifer
"Most Jews do not like to admit it, but our god is Lucifer Â- so I wasnÂ't lying Â- and we are his chosen people. Lucifer is very much aliveÂ" Harold Rosenthal http://www.thetruthseeker.co.u...
Jewish rabbi openly admits to satan worship use white children's blood they kill for passover bread, infiltrating and subverting the catholic church, creating the Jesuit order https://www.youtube.com/watch?... and https://www.youtube.com/watch?...
Barbara Spectre, a jew, tells everyone it's jews orchestrating the muslim migrant problem in Europe https://www.youtube.com/watch?v=MFE0qAiofMQ/ . No migrant raping of women in Poland. Tons in Sweden. Do the math. Use common-sense. This is to get muslims and other goyim/gentiles to wipe one another out as incompatible cultures that will clash and always have.
Rabbi A. Finkelstein ADMITS their greatest enemies are ARABS and WHITES (blacks too) whom they wish to kill one another in a 'theater of war' which they find AMUSING https://www.youtube.com/watch?...
Finkelstein also admits JEWS DID 9/11 (perpetrated by the Mossad & Bebe Netanyahu of ISRAEL) https://www.youtube.com/watch?... profiting by it (and that 3,000 jews employed there did not show up for work that day knowing about it beforehand).
Finkelstein also admits JEWS are going to destroy the U.S. Dollar and dumping it for other world currencies and gold to destroy the United States.
George Soros who funds groups to create division in the USA?? A jew. One who sold his own jew people into death for the nazis.
Zucker now FIRED @ CNN is another frying publicly for lying about "russians" and John Bonifield a producer @ CNN said it is bs. Van Jones did also.
Bernie Madoff (who made off with everyone's money, especially construction union pensions) shows the thieving nature of the JUDEN!
Michael Milken (another JEW SCAMMER junk bondsman THIEF)
Ivan Boesky
Khazar Talmudic Jews believe this of all they call goyim/gentiles (any non-jew): Jews = biggest racists of all for which they "jew guilt" you for no less! They're hypocrites known as thieves all thru history or were Argentines in the 1940 under Peron, Spanish inquistion, France (1306), Egypt (despoiled/robbed by jews), Arabs (pre & post 1948), England (1330 Edward longshanks), Romans under titus, Russia pogroms and Germany who got rid of them from their nations nazi german's too? No. Driven into DESERTS ages ago! Don't wonder why after all those exilings above.
Should anyone doubt any of this see Jacob Javits' crony Rosenthal spill the beans on it https://www.youtube.com/watch?v=D4zMVZ8HnFI/ where he called all Christianity fools for helping Israel and the biggest scam of all time per their beliefs below from their Talmud.
This is the province of the synagogue of Satan (Pharisees whom Jesus Christ himself kicked to the curb out of the temple & they killed him for it. Jeremiah did the same to them also + the Essenes could not stand them either breaking away from the pharisee corruption):
Mark Zuckerberg stole the Winklevoss twins' code for Fakebook (figures as he is a thieving low jew too).
Maria Abramovic satanist spirit cooker pal of Hillary Clinton the Voodoo queen is a jew https://www.google.com/search?...
Like Hillary Clinton's mentor Saul Alinsky author of rules for radicals book dedicated to Lucifer
"Most Jews do not like to admit it, but our god is Lucifer Â- so I wasnÂ't lying Â- and we are his chosen people. Lucifer is very much aliveÂ" Harold Rosenthal http://www.thetruthseeker.co.u...
Jewish rabbi openly admits to satan worship use white children's blood they kill for passover bread, infiltrating and subverting the catholic church, creating the Jesuit order https://www.youtube.com/watch?... and https://www.youtube.com/watch?...
Barbara Spectre, a jew, tells everyone it's jews orchestrating the muslim migrant problem in Europe https://www.youtube.com/watch?v=MFE0qAiofMQ/ . No migrant raping of women in Poland. Tons in Sweden. Do the math. Use common-sense. This is to get muslims and other goyim/gentiles to wipe one another out as incompatible cultures that will clash and always have.
Rabbi A. Finkelstein ADMITS their greatest enemies are ARABS and WHITES (blacks too) whom they wish to kill one another in a 'theater of war' which they find AMUSING https://www.youtube.com/watch?...
Finkelstein also admits JEWS DID 9/11 (perpetrated by the Mossad & Bebe Netanyahu of ISRAEL) https://www.youtube.com/watch?... profiting by it (and that 3,000 jews employed there did not show up for work that day knowing about it beforehand).
Finkelstein also admits JEWS are going to destroy the U.S. Dollar and dumping it for other world currencies and gold to destroy the United States.
George Soros who funds groups to create division in the USA?? A jew. One who sold his own jew people into death for the nazis.
Zucker now FIRED @ CNN is another frying publicly for lying about "russians" and John Bonifield a producer @ CNN said it is bs. Van Jones did also.
Bernie Madoff (who made off with everyone's money, especially construction union pensions) shows the thieving nature of the JUDEN!
Michael Milken (another JEW SCAMMER junk bondsman THIEF)
Ivan Boesky
The user is trying to download a file, better stop them, that will make them happy
To make the HTTP resource secure on a HTTPS page we can link to the resource and provide a hash of the asset or file in the HTML. HTML already supports this.
Mozilla calls it "Subresource Integrity"
NGIX has supported their own version of secure_link since back when we thought MD5 was secure:
http://nginx.org/en/docs/http/ngx_http_secure_link_module.html
This is how you make mixed content HTTPS cache friendly without giving all your security to Cloudflare or similar.
Fuck off Goolag.
Next problem please.
As long as you can exclude it from within the browser.
For example, you might be on a VPN and just using http for simplicity.
Khazar Talmudic Jews believe this of all they call goyim/gentiles (any non-jew): Jews = biggest racists of all for which they "jew guilt" you for no less! They're hypocrites known as thieves all thru history or were Argentines in the 1940 under Peron, Spanish inquistion, France (1306), Egypt (despoiled/robbed by jews), Arabs (pre & post 1948), England (1330 Edward longshanks), Romans under titus, Russia pogroms and Germany who got rid of them from their nations nazi german's too? No. Driven into DESERTS ages ago! Don't wonder why after all those exilings above.
Should anyone doubt any of this see Jacob Javits' crony Rosenthal spill the beans on it https://www.youtube.com/watch?v=D4zMVZ8HnFI/ where he called all Christianity fools for helping Israel and the biggest scam of all time per their beliefs below from their Talmud.
This is the province of the synagogue of Satan (Pharisees whom Jesus Christ himself kicked to the curb out of the temple & they killed him for it. Jeremiah did the same to them also + the Essenes could not stand them either breaking away from the pharisee corruption):
Mark Zuckerberg stole the Winklevoss twins' code for Fakebook (figures as he is a thieving low jew too).
Maria Abramovic satanist spirit cooker pal of Hillary Clinton the Voodoo queen is a jew https://www.google.com/search?...
Like Hillary Clinton's mentor Saul Alinsky author of rules for radicals book dedicated to Lucifer
"Most Jews do not like to admit it, but our god is Lucifer Â- so I wasnÂ't lying Â- and we are his chosen people. Lucifer is very much aliveÂ" Harold Rosenthal http://www.thetruthseeker.co.u...
Jewish rabbi openly admits to satan worship use white children's blood they kill for passover bread, infiltrating and subverting the catholic church, creating the Jesuit order https://www.youtube.com/watch?... and https://www.youtube.com/watch?...
Barbara Spectre, a jew, tells everyone it's jews orchestrating the muslim migrant problem in Europe https://www.youtube.com/watch?v=MFE0qAiofMQ/ . No migrant raping of women in Poland. Tons in Sweden. Do the math. Use common-sense. This is to get muslims and other goyim/gentiles to wipe one another out as incompatible cultures that will clash and always have.
Rabbi A. Finkelstein ADMITS their greatest enemies are ARABS and WHITES (blacks too) whom they wish to kill one another in a 'theater of war' which they find AMUSING https://www.youtube.com/watch?...
Finkelstein also admits JEWS DID 9/11 (perpetrated by the Mossad & Bebe Netanyahu of ISRAEL) https://www.youtube.com/watch?... profiting by it (and that 3,000 jews employed there did not show up for work that day knowing about it beforehand).
Finkelstein also admits JEWS are going to destroy the U.S. Dollar and dumping it for other world currencies and gold to destroy the United States.
George Soros who funds groups to create division in the USA?? A jew. One who sold his own jew people into death for the nazis.
Zucker now FIRED @ CNN is another frying publicly for lying about "russians" and John Bonifield a producer @ CNN said it is bs. Van Jones did also.
Bernie Madoff (who made off with everyone's money, especially construction union pensions) shows the thieving nature of the JUDEN!
Michael Milken (another JEW SCAMMER junk bondsman THIEF)
Ivan Boesky
Khazar Talmudic Jews believe this of all they call goyim/gentiles (any non-jew): Jews = biggest racists of all for which they "jew guilt" you for no less! They're hypocrites known as thieves all thru history or were Argentines in the 1940 under Peron, Spanish inquistion, France (1306), Egypt (despoiled/robbed by jews), Arabs (pre & post 1948), England (1330 Edward longshanks), Romans under titus, Russia pogroms and Germany who got rid of them from their nations nazi german's too? No. Driven into DESERTS ages ago! Don't wonder why after all those exilings above.
Should anyone doubt any of this see Jacob Javits' crony Rosenthal spill the beans on it https://www.youtube.com/watch?v=D4zMVZ8HnFI/ where he called all Christianity fools for helping Israel and the biggest scam of all time per their beliefs below from their Talmud.
This is the province of the synagogue of Satan (Pharisees whom Jesus Christ himself kicked to the curb out of the temple & they killed him for it. Jeremiah did the same to them also + the Essenes could not stand them either breaking away from the pharisee corruption):
Mark Zuckerberg stole the Winklevoss twins' code for Fakebook (figures as he is a thieving low jew too).
Maria Abramovic satanist spirit cooker pal of Hillary Clinton the Voodoo queen is a jew https://www.google.com/search?...
Like Hillary Clinton's mentor Saul Alinsky author of rules for radicals book dedicated to Lucifer
"Most Jews do not like to admit it, but our god is Lucifer Â- so I wasnÂ't lying Â- and we are his chosen people. Lucifer is very much aliveÂ" Harold Rosenthal http://www.thetruthseeker.co.u...
Jewish rabbi openly admits to satan worship use white children's blood they kill for passover bread, infiltrating and subverting the catholic church, creating the Jesuit order https://www.youtube.com/watch?... and https://www.youtube.com/watch?...
Barbara Spectre, a jew, tells everyone it's jews orchestrating the muslim migrant problem in Europe https://www.youtube.com/watch?v=MFE0qAiofMQ/ . No migrant raping of women in Poland. Tons in Sweden. Do the math. Use common-sense. This is to get muslims and other goyim/gentiles to wipe one another out as incompatible cultures that will clash and always have.
Rabbi A. Finkelstein ADMITS their greatest enemies are ARABS and WHITES (blacks too) whom they wish to kill one another in a 'theater of war' which they find AMUSING https://www.youtube.com/watch?...
Finkelstein also admits JEWS DID 9/11 (perpetrated by the Mossad & Bebe Netanyahu of ISRAEL) https://www.youtube.com/watch?... profiting by it (and that 3,000 jews employed there did not show up for work that day knowing about it beforehand).
Finkelstein also admits JEWS are going to destroy the U.S. Dollar and dumping it for other world currencies and gold to destroy the United States.
George Soros who funds groups to create division in the USA?? A jew. One who sold his own jew people into death for the nazis.
Zucker now FIRED @ CNN is another frying publicly for lying about "russians" and John Bonifield a producer @ CNN said it is bs. Van Jones did also.
Bernie Madoff (who made off with everyone's money, especially construction union pensions) shows the thieving nature of the JUDEN!
Michael Milken (another JEW SCAMMER junk bondsman THIEF)
Ivan Boesky
The purpose of the cert is for the browser to know whether they are talking to your server, or to my MITM proxy which I made on a Raspberry Pi, ans presents itself as a WiFi network "Convention Guest WiFi".
If you don't tell the browser WHICH cert you've rolled, it's unable to distinguish your cert from my imposter cert, and therefore you have almost zero security.
> you suggest the common user can tell the difference between a cardboard box and a safe. They can't (thus the green locks and such)
I suspect users can see a green lock and have some idea what it means.
The green lock is there because the user doesn't know the difference between http: and https: in the URL bar. As such, the browser should display the green lock for an HTTPS connection with a valid cert and not display one for an HTTP connection or an HTTPS connection with an invalid cert. It's even easier for your RasPi to MITM an HTTP connection, but the browser will happily use that protocol without complaint.
"When information is power, privacy is freedom" - Jah-Wren Ryel
You just get one of hundreds of CAs to issue you a cert by MITMing their automated DNS/Website flag planting procedure
Would these be CAs that submit all issued certificates to Certificate Transparency or CAs that do not?
.exe files are harmless on Linux
Unless the user has installed Wine. Valve's Proton distribution of Wine will only make Wine more commonplace among users of X11/Linux.
encrypted traffic can't use the internet's caching infrastructure which would benefit popular downloads
A CDN contracted by the operator of the origin server, such as CloudFront or Cloudflare, can cache HTTPS just as easily as cleartext HTTP.
Just dont use Chrome or dont update.
Jew Brin and Jew Page and Jew CEO of YouTube always want to decide for you. Jews always do.
It's Jew shit. Fake religion fake people.
I only troll, trolls. For whom does the troll really troll.
- JIDF try to tire you out.
https://en.wikipedia.org/wiki/Jewish_Internet_Defense_Force
tl;dr already got it a long time ago
Hmm Yiddish is actually 80% German. I am German and I can understand it. It sounds like a German dialect, and I only fail to understand some of the Hebrew and Polish words sprinkled in. This such a plain and well-known fact and even that you get wrong. Sheesh.
There are two rules for success:
1. Never tell everything you know.
HTTP is not unsecure. Publicly readable data is just that. Once again management is confusing complicated with secure. Once again they are wrong.
I named mine Fred.
Then the kids wanted to adopt him...
As long as it continues to let me download FirefoxSetup.exe, we're good.
go back and sleep with your sister and your mother again, they miss you pin dick
Gmail already gimped the send file function of Gmail to the point of near uselessness. "No sending .zip files for you! And don't bother renaming the extention because we check the file format itself. HAHA!" A hex editor can get around this, but why do we have to resort to this shit?
Now Google wants to do the same to their web browser like they did with Gmail. No thanks.
Chrome will be shitlisted as a near useless toy when they pull this.
What they plan to do right now is a step in that direction. Wait until it gets to the point that all downloads of that kind are banned no matter where they came from, just like Gmail. These days, I don't trust Google to not do this.
Google really needs to go back to "Do no evil" and brand itself with a red hot iron of this phrase
to make sure they remember that.
Starks are supposed to be much more honourable. Just goes on to prove that there are bad apples in every yard.
While I get the security pitch for TLS everywhere, there is a side effect to that.
In effect bandwidth consumption will increase as it is hard to cache artifacts on a https URL unless you (as the one wanting to cache) also control all the clients, and have your certificates installed on them.
http://myactivity.google.com was a wake up call for me. The amount of data they collect about users by default is outrageous The problem is that using their software as a middle man to access the Internet, both on you computers and mobile devices presents them with a unique opportunity to collecting all your browsing data. Https traffic may be encrypted, but de-crypted as soon as Google's slimey software gets at it. Encryption merely prevents Google's competitors from accessing that data.
Many malicious sites are using HTTPS. Many sites using HTTPS are infected to be malicious or deliver malicious content. Obtaining a valid SSL certificate can be done for free and takes moments. Google seem to be focusing very much on the "well, we tried" method of security awareness, rather than actually improving security for users experience. It seems to me as though they don't want to be lumped in with the blame game the next time there's a significant flaw exploited; they're taking "action" to "improve security" knowing full well that it's going to be entirely ineffective. As long as they can publicly point to the changes they're making and make some claim that they've been effective to some degree then they're seen as being helpful, even when they're objectively not.
The pantomime of online security is turning more and more farcical as the days go by. Pretty soon the farce will turn in to tragedy I'm sure, as more and more users believe that security upgrades mean that they don't need to be individually aware of what is the best thing to do or the safe way to browse.
By applying TLS, the site operators are essentially declaring that the content needs to be protected and claiming that it is protected.
No. By applying TLS the site operators are protecting the content but not making any declarations or claims. By using plain HTTP you are effectively claiming that the content is protected but not actually protecting it. You mixed up the two situations in your explanation.
Proper declarations of security or identity are made with the various levels CA certificates.
The problem with browsers at the moment is they mix the signals and communicate the wrong expectations to the user, and then when the miscommunication leads the user to make an incorrect assumption the browsers compensate by doubling down on the misinformation and actively pushing everyone toward the worst possible reaction.
why not include office documents and pdf's as well? they've been a source of infections too.
well, not much else is left except pure media (video/audi/pictures) files.
On a long enough timeline, the survival rate for everyone drops to zero.
If Google wants to protect people from the wild west that is the Internet then sure. But dang it leave the Intranets of companies and homes alone!
Hey kids, this is what mental illness looks like! ^^^