Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > alt.comp.software.firefox > #419
| From | Eli the Bearded <*@eli.users.panix.com> |
|---|---|
| Newsgroups | alt.comp.software.firefox |
| Subject | Re: Firefox ESR |
| Date | 2021-04-28 21:02 +0000 |
| Organization | Some absurd concept |
| Message-ID | <eli$2104281702@qaz.wtf> (permalink) |
| References | <s6akrj$di4$8@dont-email.me> <lzn6c3qs59j0$.dlg@v.nguard.lh> <XLb1pIPDTZigFwYM@255soft.uk> <fr7vhjq8uft6$.dlg@v.nguard.lh> |
In alt.comp.software.firefox, VanguardLH <invalid@invalid.invalid> wrote: > Yes, they're already in the process for removing HTTP-only support. > Look in about:preferences#privacy and scroll to the bottom. I've tried > the "Enable HTTPS-Only Mode in all windows", but I've hit too many HTTP > only sites where I had to okay the intervening the prompt. I have seen that but I don't see that as step towards removing HTTP-only support but instead a step towards helping people protect themselves from HTTP-only security issues. Because of embedded http servers in hardware devices, I suspect HTTP-only support is going to be needed for a LONG time. Let's Encrypt and the like is good for things that can reach the internet, but stuff that is intended to be local network only will not be as easy to secure. > Many sites cannot afford SSL/TLS certificates. Those can only be > leased: you buy them for a fixed term, and have to pay to renew. That > was then. Now there are some free or cheap CAs (Certificate > Authorities). ZeroSSL is free, requires renewal within 90 days, but you > can use their client for auto-renewal (max of 3 certs in free plan). > Let's Encrypt (and SSL For Free which using Let's Encrypt) are free. The short renewal time on free SSL certs is part of a tradeoff for reduced scrutiny about who is getting the cert. Someone who gets one via nefarious means will have a smaller window to operate with it. FWIW, I did an audit of my spam about two years ago and found that email trying to get me to go to an http site (instead of an https site) was about 98% correlated with email being spam. (A lot of spam at the time -- and possibly now but I haven't checked recently -- was trying to use the small window of time between when a domain could first be resolved at the DNS root and when any other information about the domain is available. Beause of that tight window, the time to get an SSL cert becomes expensive, even one as fast as Let's Encrypt.) > Cloudflare doles out free certs. So, there really isn't an excuse not > to have an HTTPS site other than, yeah, it requires a more effort or > expertise to setup correctly. I don't really want the built-in webserver in my printer talking to the internet, because I don't trust that someone couldn't find a way to run code or siphon information out of it. I do want my printer on the local net so I can print without being physically next to the machine. And since I reach it at http://192.168.1.168/ I can't even get a cert: there's no domain name and no hostname, just an IP address likely used by thousands of other devices. (Further, I don't really care that my printer _has_ a built-in webserver, since I only print to it using IPP. But it does speak on port 80 and I've used it while searching for obscure settings, and presumably some people do use it.) > A lot of sites are web hosted. They don't provide their own resources, > and instead contract with a web hosting provider to supply the web site. > The web hoster would have to provide some means of allowing certs at > each site which, my guess, means each web-hosted HTTPS site would have > to register its own domain (even if free from the web hoster) to allow a > cert that is defined for just that domain. The standard Let's Encrypt proof of domain ownership is being able to place a specially crafted file at a particular "well known" location at a particular time (namely within a few seconds of asking for a cert). The domain registrars don't need to get involved at all. More advanced Let's Encrypt proof of domain ownership involves DNS record changes (well-known and at a particular time). I've set that up in order to get a wildcard cert (*.example.com for all first level subdomains of example.com). Again the domain registrars are not involved. Elijah ------ imagines there are a lot of people with a lot of http only home devices
Back to alt.comp.software.firefox | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread
Firefox ESR Michael Trew <mt999999@ymail.com> - 2021-04-27 23:29 -0400
Re: Firefox ESR Michael Trew <mt999999@ymail.com> - 2021-04-27 23:30 -0400
Re: Firefox ESR VanguardLH <V@nguard.LH> - 2021-04-27 23:27 -0500
Re: Firefox ESR Andy Burns <usenet@andyburns.uk> - 2021-04-28 07:13 +0100
Re: Firefox ESR Andy Burns <usenet@andyburns.uk> - 2021-04-28 07:17 +0100
Re: Firefox ESR VanguardLH <V@nguard.LH> - 2021-04-28 02:01 -0500
Re: Firefox ESR VanguardLH <V@nguard.LH> - 2021-04-28 02:03 -0500
Firefox ESR Dave <dave@triffid.co.uk> - 2021-04-28 08:57 +0100
Re: Firefox ESR Andy Burns <usenet@andyburns.uk> - 2021-04-28 10:39 +0100
Firefox ESR Dave <dave@triffid.co.uk> - 2021-04-28 14:49 +0100
Re: Firefox ESR PietB <www.godfatherof.nl/@opt-in.invalid> - 2021-04-28 10:00 +0200
Re: Firefox ESR "J. P. Gilliver (John)" <G6JPG@255soft.uk> - 2021-04-28 18:00 +0100
Re: Firefox ESR PietB <www.godfatherof.nl/@opt-in.invalid> - 2021-04-28 20:55 +0200
Re: Firefox ESR VanguardLH <V@nguard.LH> - 2021-04-28 14:50 -0500
Re: Firefox ESR Dave Royal<dave@dave123royal.com> - 2021-04-28 20:46 +0000
Re: Firefox ESR "J. P. Gilliver (John)" <G6JPG@255soft.uk> - 2021-04-28 21:54 +0100
Re: Firefox ESR Eli the Bearded <*@eli.users.panix.com> - 2021-04-28 21:02 +0000
Re: Firefox ESR VanguardLH <V@nguard.LH> - 2021-04-29 00:12 -0500
Keywords header (was: Re: Firefox ESR) Eli the Bearded <*@eli.users.panix.com> - 2021-04-29 17:37 +0000
Re: Keywords header VanguardLH <V@nguard.LH> - 2021-05-06 05:52 -0500
Re: Keywords header VanguardLH <V@nguard.LH> - 2021-05-06 06:06 -0500
Re: Keywords header !@!.invalid (Ï) - 2021-05-06 14:39 +0100
Re: Keywords header "Adam H. Kerman" <ahk@chinet.com> - 2021-05-06 15:14 +0000
Re: Keywords header "J. P. Gilliver (John)" <G6JPG@255soft.uk> - 2021-05-06 18:04 +0100
Re: Keywords header VanguardLH <V@nguard.LH> - 2021-05-08 15:01 -0500
Re: Keywords header "Adam H. Kerman" <ahk@chinet.com> - 2021-05-08 21:08 +0000
Re: Keywords header VanguardLH <V@nguard.LH> - 2021-05-08 16:37 -0500
Re: Keywords header !@!.invalid (Ï) - 2021-05-08 22:52 +0100
Re: Keywords header Frank Slootweg <this@ddress.is.invalid> - 2021-05-06 17:49 +0000
Re: Keywords header VanguardLH <V@nguard.LH> - 2021-05-08 15:40 -0500
Re: Keywords header Miguel Tomar Nogueira <mnogueira@mail.telepac.pt> - 2021-05-09 05:58 +0000
Re: Keywords header Frank Slootweg <this@ddress.is.invalid> - 2021-05-09 17:24 +0000
Re: Keywords header Eli the Bearded <*@eli.users.panix.com> - 2021-05-06 18:11 +0000
Panix spammifying of submissions (was: Keywords header) VanguardLH <V@nguard.LH> - 2021-05-08 16:30 -0500
Re: Panix spammifying of submissions (was: Keywords header) danny burstein <dannyb@panix.com> - 2021-05-08 21:52 +0000
Re: Panix spammifying of submissions (was: Keywords header) Eli the Bearded <*@eli.users.panix.com> - 2021-05-10 02:34 +0000
Re: Firefox ESR Michael Trew <mt999999@ymail.com> - 2021-04-28 13:52 -0400
Re: Firefox ESR Eli the Bearded <*@eli.users.panix.com> - 2021-04-28 18:29 +0000
Re: Firefox ESR Michael Trew <mt999999@ymail.com> - 2021-04-28 23:26 -0400
Re: Firefox ESR Rich <rich@example.invalid> - 2021-04-29 12:52 +0000
Re: Firefox ESR Rich <rich@example.invalid> - 2021-04-29 12:45 +0000
Re: Firefox ESR "Adam H. Kerman" <ahk@chinet.com> - 2021-04-29 13:22 +0000
Re: Firefox ESR Rich <rich@example.invalid> - 2021-04-29 13:53 +0000
Re: Firefox ESR "Adam H. Kerman" <ahk@chinet.com> - 2021-04-29 18:32 +0000
Re: Firefox ESR Rich <rich@example.invalid> - 2021-04-29 20:31 +0000
Re: Firefox ESR "OldbieOne" <me@here.com> - 2021-05-03 14:17 -0400
Re: Firefox ESR PietB <www.godfatherof.nl/@opt-in.invalid> - 2021-05-08 16:58 +0200
Re: Firefox ESR "OldbieOne" <me@here.com> - 2021-05-19 10:52 -0400
Re: Firefox ESR Ant <ant@zimage.comANT> - 2021-05-19 09:10 -0700
Re: Firefox ESR "Adam H. Kerman" <ahk@chinet.com> - 2021-05-19 16:35 +0000
Re: Firefox ESR "OldbieOne" <me@here.com> - 2021-05-19 15:16 -0400
Re: Firefox ESR Job Bautista <jobbautista9@aol.com> - 2021-05-20 18:35 +0800
Re: Firefox ESR "OldbieOne" <me@here.com> - 2021-05-25 12:32 -0400
Re: Firefox ESR WaltS48 <schw01@invalid.net> - 2021-05-25 15:16 -0400
Re: Firefox ESR Miguel Tomar Nogueira <mnogueira@mail.telepac.pt> - 2021-05-09 06:18 +0000
Re: Firefox ESR chris@here.com - 2021-04-27 23:31 -0500
Re: Firefox ESR Michael Trew <mt999999@ymail.com> - 2021-04-28 13:53 -0400
Re: Firefox ESR VanguardLH <V@nguard.LH> - 2021-04-27 23:26 -0500
csiph-web