HN user

andyjh

52 karma
Posts1
Comments15
View on HN

Licensing issues aside, it would cost _additional_ money to actually serve all that content to a global audience (shipping bytes over the internet isn't free).

BBC.com Is Down 5 years ago

It would also be useful if you can tell us which IP you're connecting to when you see the error (eg from dev tools).

Why No HTTPS? 8 years ago

Chrome isn't forcing anyone, it's just making it clear to users that a non-https site is insecure, which it is. What's the problem with providing information so that users can make an informed choice about whether to use the site?

Not true: Currently the "info" indicator appears on first interaction (which _could_ be after they've auto-completed everything, but may not be). This is changing though: In Chrome 68 the info indicator will be there on all HTTP pages, without form interaction required. So this change just changes it from "info" to red warning.

No, as of chrome 68, http will be marked as not secure without waiting for any user interaction at all. The change for http pages outlined in this post is to upgrade that from the grey info message to a red warning.

I'm personally glad Mozilla take such an interest in ensuring CAs are trustworthy. After all, they are the linchpin for security and authenticity of just about everything on the web.

I think this post shows that Mozilla are trying to be as transparent as possible about what they expect, and thay they're proactively working with Digicert to make it as likely as possible that the new CA will be trusted. A certain amount of open-endedness is inevitable though, otherwise it'd be possible to find loopholes with enough motivation (and the survival of a business is fairly good motivation).

"...the leaked information is from any website which was using the service..."

Potentially, yes. Not just HTTPS, but those are obviously the more worrying cases.

It's not possible to know the totality of information that has been leaked, though efforts are being made to try and list affected / potentially affected sites.[1]

My advice would be: For any sites you're worried about (ie hosted on CF and you have an account), log out of all sessions on all devices, and reset your password. Don't share passwords between sites either; if you're using 1password now, you can use unique & complex passwords for everything.

[1] eg https://github.com/pirate/sites-using-cloudflare