Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > alt.comp.software.firefox > #419

Re: Firefox ESR

From Eli the Bearded <*@eli.users.panix.com>
Newsgroups alt.comp.software.firefox
Subject Re: Firefox ESR
Date 2021-04-28 21:02 +0000
Organization Some absurd concept
Message-ID <eli$2104281702@qaz.wtf> (permalink)
References <s6akrj$di4$8@dont-email.me> <lzn6c3qs59j0$.dlg@v.nguard.lh> <XLb1pIPDTZigFwYM@255soft.uk> <fr7vhjq8uft6$.dlg@v.nguard.lh>

Show all headers | View raw


In alt.comp.software.firefox, VanguardLH  <invalid@invalid.invalid> wrote:
> Yes, they're already in the process for removing HTTP-only support.
> Look in about:preferences#privacy and scroll to the bottom.  I've tried
> the "Enable HTTPS-Only Mode in all windows", but I've hit too many HTTP
> only sites where I had to okay the intervening the prompt.

I have seen that but I don't see that as step towards removing HTTP-only
support but instead a step towards helping people protect themselves
from HTTP-only security issues.

Because of embedded http servers in hardware devices, I suspect
HTTP-only support is going to be needed for a LONG time. Let's Encrypt
and the like is good for things that can reach the internet, but stuff
that is intended to be local network only will not be as easy to secure.

> Many sites cannot afford SSL/TLS certificates.  Those can only be
> leased: you buy them for a fixed term, and have to pay to renew.  That
> was then.  Now there are some free or cheap CAs (Certificate
> Authorities).  ZeroSSL is free, requires renewal within 90 days, but you
> can use their client for auto-renewal (max of 3 certs in free plan).
> Let's Encrypt (and SSL For Free which using Let's Encrypt) are free.

The short renewal time on free SSL certs is part of a tradeoff for
reduced scrutiny about who is getting the cert. Someone who gets one via
nefarious means will have a smaller window to operate with it.

FWIW, I did an audit of my spam about two years ago and found that email
trying to get me to go to an http site (instead of an https site) was
about 98% correlated with email being spam.

(A lot of spam at the time -- and possibly now but I haven't checked
recently -- was trying to use the small window of time between when a
domain could first be resolved at the DNS root and when any other
information about the domain is available. Beause of that tight window,
the time to get an SSL cert becomes expensive, even one as fast as Let's
Encrypt.)

> Cloudflare doles out free certs.  So, there really isn't an excuse not
> to have an HTTPS site other than, yeah, it requires a more effort or
> expertise to setup correctly.

I don't really want the built-in webserver in my printer talking to the
internet, because I don't trust that someone couldn't find a way to run
code or siphon information out of it. I do want my printer on the local
net so I can print without being physically next to the machine. And
since I reach it at http://192.168.1.168/ I can't even get a cert:
there's no domain name and no hostname, just an IP address likely used
by thousands of other devices.

(Further, I don't really care that my printer _has_ a built-in
webserver, since I only print to it using IPP. But it does speak on port
80 and I've used it while searching for obscure settings, and presumably
some people do use it.)

> A lot of sites are web hosted.  They don't provide their own resources,
> and instead contract with a web hosting provider to supply the web site.
> The web hoster would have to provide some means of allowing certs at
> each site which, my guess, means each web-hosted HTTPS site would have
> to register its own domain (even if free from the web hoster) to allow a
> cert that is defined for just that domain.

The standard Let's Encrypt proof of domain ownership is being able to
place a specially crafted file at a particular "well known" location at
a particular time (namely within a few seconds of asking for a cert).
The domain registrars don't need to get involved at all.

More advanced Let's Encrypt proof of domain ownership involves DNS
record changes (well-known and at a particular time). I've set that up
in order to get a wildcard cert (*.example.com for all first level
subdomains of example.com). Again the domain registrars are not
involved.

Elijah
------
imagines there are a lot of people with a lot of http only home devices

Back to alt.comp.software.firefox | Previous | NextPrevious in thread | Next in thread | Find similar | Unroll thread


Thread

Firefox ESR Michael Trew <mt999999@ymail.com> - 2021-04-27 23:29 -0400
  Re: Firefox ESR Michael Trew <mt999999@ymail.com> - 2021-04-27 23:30 -0400
    Re: Firefox ESR VanguardLH <V@nguard.LH> - 2021-04-27 23:27 -0500
      Re: Firefox ESR Andy Burns <usenet@andyburns.uk> - 2021-04-28 07:13 +0100
        Re: Firefox ESR Andy Burns <usenet@andyburns.uk> - 2021-04-28 07:17 +0100
        Re: Firefox ESR VanguardLH <V@nguard.LH> - 2021-04-28 02:01 -0500
          Re: Firefox ESR VanguardLH <V@nguard.LH> - 2021-04-28 02:03 -0500
          Firefox ESR Dave <dave@triffid.co.uk> - 2021-04-28 08:57 +0100
            Re: Firefox ESR Andy Burns <usenet@andyburns.uk> - 2021-04-28 10:39 +0100
              Firefox ESR Dave <dave@triffid.co.uk> - 2021-04-28 14:49 +0100
        Re: Firefox ESR PietB <www.godfatherof.nl/@opt-in.invalid> - 2021-04-28 10:00 +0200
      Re: Firefox ESR "J. P. Gilliver (John)" <G6JPG@255soft.uk> - 2021-04-28 18:00 +0100
        Re: Firefox ESR PietB <www.godfatherof.nl/@opt-in.invalid> - 2021-04-28 20:55 +0200
        Re: Firefox ESR VanguardLH <V@nguard.LH> - 2021-04-28 14:50 -0500
          Re: Firefox ESR Dave Royal<dave@dave123royal.com> - 2021-04-28 20:46 +0000
          Re: Firefox ESR "J. P. Gilliver (John)" <G6JPG@255soft.uk> - 2021-04-28 21:54 +0100
          Re: Firefox ESR Eli the Bearded <*@eli.users.panix.com> - 2021-04-28 21:02 +0000
            Re: Firefox ESR VanguardLH <V@nguard.LH> - 2021-04-29 00:12 -0500
              Keywords header (was: Re: Firefox ESR) Eli the Bearded <*@eli.users.panix.com> - 2021-04-29 17:37 +0000
                Re: Keywords header VanguardLH <V@nguard.LH> - 2021-05-06 05:52 -0500
                Re: Keywords header VanguardLH <V@nguard.LH> - 2021-05-06 06:06 -0500
                Re: Keywords header !@!.invalid (Ï) - 2021-05-06 14:39 +0100
                Re: Keywords header "Adam H. Kerman" <ahk@chinet.com> - 2021-05-06 15:14 +0000
                Re: Keywords header "J. P. Gilliver (John)" <G6JPG@255soft.uk> - 2021-05-06 18:04 +0100
                Re: Keywords header VanguardLH <V@nguard.LH> - 2021-05-08 15:01 -0500
                Re: Keywords header "Adam H. Kerman" <ahk@chinet.com> - 2021-05-08 21:08 +0000
                Re: Keywords header VanguardLH <V@nguard.LH> - 2021-05-08 16:37 -0500
                Re: Keywords header !@!.invalid (Ï) - 2021-05-08 22:52 +0100
                Re: Keywords header Frank Slootweg <this@ddress.is.invalid> - 2021-05-06 17:49 +0000
                Re: Keywords header VanguardLH <V@nguard.LH> - 2021-05-08 15:40 -0500
                Re: Keywords header Miguel Tomar Nogueira <mnogueira@mail.telepac.pt> - 2021-05-09 05:58 +0000
                Re: Keywords header Frank Slootweg <this@ddress.is.invalid> - 2021-05-09 17:24 +0000
                Re: Keywords header Eli the Bearded <*@eli.users.panix.com> - 2021-05-06 18:11 +0000
                Panix spammifying of submissions (was: Keywords header) VanguardLH <V@nguard.LH> - 2021-05-08 16:30 -0500
                Re: Panix spammifying of submissions (was: Keywords header) danny burstein <dannyb@panix.com> - 2021-05-08 21:52 +0000
                Re: Panix spammifying of submissions (was: Keywords header) Eli the Bearded <*@eli.users.panix.com> - 2021-05-10 02:34 +0000
      Re: Firefox ESR Michael Trew <mt999999@ymail.com> - 2021-04-28 13:52 -0400
        Re: Firefox ESR Eli the Bearded <*@eli.users.panix.com> - 2021-04-28 18:29 +0000
          Re: Firefox ESR Michael Trew <mt999999@ymail.com> - 2021-04-28 23:26 -0400
            Re: Firefox ESR Rich <rich@example.invalid> - 2021-04-29 12:52 +0000
        Re: Firefox ESR Rich <rich@example.invalid> - 2021-04-29 12:45 +0000
          Re: Firefox ESR "Adam H. Kerman" <ahk@chinet.com> - 2021-04-29 13:22 +0000
            Re: Firefox ESR Rich <rich@example.invalid> - 2021-04-29 13:53 +0000
              Re: Firefox ESR "Adam H. Kerman" <ahk@chinet.com> - 2021-04-29 18:32 +0000
                Re: Firefox ESR Rich <rich@example.invalid> - 2021-04-29 20:31 +0000
            Re: Firefox ESR "OldbieOne" <me@here.com> - 2021-05-03 14:17 -0400
              Re: Firefox ESR PietB <www.godfatherof.nl/@opt-in.invalid> - 2021-05-08 16:58 +0200
                Re: Firefox ESR "OldbieOne" <me@here.com> - 2021-05-19 10:52 -0400
                Re: Firefox ESR Ant <ant@zimage.comANT> - 2021-05-19 09:10 -0700
                Re: Firefox ESR "Adam H. Kerman" <ahk@chinet.com> - 2021-05-19 16:35 +0000
                Re: Firefox ESR "OldbieOne" <me@here.com> - 2021-05-19 15:16 -0400
                Re: Firefox ESR Job Bautista <jobbautista9@aol.com> - 2021-05-20 18:35 +0800
                Re: Firefox ESR "OldbieOne" <me@here.com> - 2021-05-25 12:32 -0400
                Re: Firefox ESR WaltS48 <schw01@invalid.net> - 2021-05-25 15:16 -0400
          Re: Firefox ESR Miguel Tomar Nogueira <mnogueira@mail.telepac.pt> - 2021-05-09 06:18 +0000
    Re: Firefox ESR chris@here.com - 2021-04-27 23:31 -0500
      Re: Firefox ESR Michael Trew <mt999999@ymail.com> - 2021-04-28 13:53 -0400
  Re: Firefox ESR VanguardLH <V@nguard.LH> - 2021-04-27 23:26 -0500

csiph-web