Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.user > #257262

Re: Apt sources.list

From Jeffrey Walton <noloader@gmail.com>
Newsgroups linux.debian.user
Subject Re: Apt sources.list
Date 2023-04-16 02:40 +0200
Message-ID <GkYAV-2iMo-1@gated-at.bofh.it> (permalink)
References <GkN2N-2bXs-5@gated-at.bofh.it> <GkNct-2c13-1@gated-at.bofh.it> <GkNFv-2cbI-3@gated-at.bofh.it> <GkOid-2cEI-1@gated-at.bofh.it> <GkPHj-2dFR-5@gated-at.bofh.it>
Organization linux.* mail to news gateway

Show all headers | View raw


On Sat, Apr 15, 2023 at 11:09 AM <paulf@quillandmouse.com> wrote:
> On Sat, 15 Apr 2023 14:01:27 +0100
> Alain D D Williams <addw@phcomp.co.uk> wrote:
> > On Sat, Apr 15, 2023 at 08:52:06AM -0400, Greg Wooledge wrote:
> > While we are talking about this, is there any reason why all the
> > http: should not be https: ?
> >
> > I have done this on my own machine without ill effect.
>
> Okay. Let's open this can of worms. The ONLY reason https is used on
> most sites is because Google *mandated* it years ago. ("Mandate" means
> we'll downgrade your search ranking if you don't use https.) There is
> otherwise no earthly reason to have an encrypted connection to a web
> server unless there is some exchange of private information between you
> and the server.
>
> Reading through all of Google's explanations, I've never seen a
> satisfactory explanation for this change. With that in mind, I believe
> the Debian gods did the right thing in leaving their web connections
> "insecure". Though, in truth, the integrity of Debian server contents
> wouldn't be changed in the slightest whether the connection was
> encrypted or not.

The change came after Snowden released his cache of documents and the
world learned how pervasive snooping is by the US government. There's
nothing special about the US government, and we know other governments
were doing it, too.

I think Snowden accelerated HTTPS adoption or pushed it over the top.
The browsers were interested in encrypting communications for years
because of the "free ISPs". The ones like NetZero that provided no
cost dialup or broadband, but monitored connections and injected
JavaScript into web pages.

Not only did it happen with HTTPS, it also happened in mail protocols.
Google stopped accepting plain text SMTP connections, too.

I think the browsers did a pretty good job of forcing folks to use
encrypted channels. I think it helped secure content for most users.

One size did not fit all. I watched some browser engineers bully folks
on the Web Crypto mailing list pushing the "HTTPS Everywhere" agenda.
One fellow bullied was Mark Watson who tried to argue NetFlix only
needed encrypted comms part of the time (like login and streaming
content). The Google engineers' treatment of folks with non-conforming
viewpoints was awful.

Jeff

Back to linux.debian.user | Previous | NextPrevious in thread | Next in thread | Find similar | Unroll thread


Thread

Apt sources.list <paulf@quillandmouse.com> - 2023-04-15 14:20 +0200
  Re: Apt sources.list Brian <ad44@cityscape.co.uk> - 2023-04-15 14:30 +0200
    Re: Apt sources.list Greg Wooledge <greg@wooledge.org> - 2023-04-15 15:00 +0200
      Re: Apt sources.list Alain D D Williams <addw@phcomp.co.uk> - 2023-04-15 15:40 +0200
        Re: Apt sources.list <tomas@tuxteam.de> - 2023-04-15 15:50 +0200
          Re: Apt sources.list Alain D D Williams <addw@phcomp.co.uk> - 2023-04-15 16:10 +0200
            Re: Apt sources.list <tomas@tuxteam.de> - 2023-04-15 16:20 +0200
        Re: Apt sources.list Brian <ad44@cityscape.co.uk> - 2023-04-15 16:10 +0200
        Re: Apt sources.list Charles Curley <charlescurley@charlescurley.com> - 2023-04-15 16:50 +0200
        Re: Apt sources.list <paulf@quillandmouse.com> - 2023-04-15 17:10 +0200
          Re: Apt sources.list Dan Ritter <dsr@randomstring.org> - 2023-04-15 18:40 +0200
            Re: Apt sources.list <tomas@tuxteam.de> - 2023-04-15 19:50 +0200
              Re: Apt sources.list davidson <davidson@freevolt.org> - 2023-04-16 01:00 +0200
                Re: Apt sources.list Greg Wooledge <greg@wooledge.org> - 2023-04-16 01:20 +0200
                Re: Apt sources.list The Wanderer <wanderer@fastmail.fm> - 2023-04-16 01:30 +0200
                Re: Apt sources.list Stefan Monnier <monnier@iro.umontreal.ca> - 2023-04-16 02:30 +0200
                Re: Apt sources.list davidson <davidson@freevolt.org> - 2023-04-16 02:20 +0200
                Re: Apt sources.list Tim Woodall <debianuser@woodall.me.uk> - 2023-04-16 21:10 +0200
                Re: Apt sources.list Jeffrey Walton <noloader@gmail.com> - 2023-04-16 23:00 +0200
                Re: Apt sources.list Jeffrey Walton <noloader@gmail.com> - 2023-04-17 03:30 +0200
                Re: Apt sources.list <tomas@tuxteam.de> - 2023-04-17 06:50 +0200
                Re: Apt sources.list Jeffrey Walton <noloader@gmail.com> - 2023-04-17 17:10 +0200
                Re: Apt sources.list <tomas@tuxteam.de> - 2023-04-16 07:40 +0200
                Re: Apt sources.list Eduardo M KALINOWSKI <eduardo@kalinowski.com.br> - 2023-04-16 14:10 +0200
          Re: Apt sources.list Alain D D Williams <addw@phcomp.co.uk> - 2023-04-15 20:30 +0200
            Re: Apt sources.list Brian <ad44@cityscape.co.uk> - 2023-04-15 20:40 +0200
            Re: Apt sources.list Andy Smith <andy@strugglers.net> - 2023-04-15 22:00 +0200
          Re: Apt sources.list Charles Curley <charlescurley@charlescurley.com> - 2023-04-15 20:50 +0200
          Re: Apt sources.list Jeffrey Walton <noloader@gmail.com> - 2023-04-16 02:40 +0200
            Re: Apt sources.list <paulf@quillandmouse.com> - 2023-04-16 14:50 +0200
    Re: Apt sources.list <paulf@quillandmouse.com> - 2023-04-15 16:50 +0200
    Re: Apt sources.list "Andrew M.A. Cater" <amacater@einval.com> - 2023-04-15 18:50 +0200
      Re: Apt sources.list Brian <ad44@cityscape.co.uk> - 2023-04-15 21:20 +0200
        Re: Apt sources.list "Andrew M.A. Cater" <amacater@einval.com> - 2023-04-15 22:20 +0200
          Re: Apt sources.list songbird <songbird@anthive.com> - 2023-04-16 00:00 +0200
          Re: Apt sources.list Stefan Monnier <monnier@iro.umontreal.ca> - 2023-04-16 06:20 +0200
            Re: Apt sources.list David Wright <deblis@lionunicorn.co.uk> - 2023-04-16 07:00 +0200
            Re: Apt sources.list "Andrew M.A. Cater" <amacater@einval.com> - 2023-04-16 13:20 +0200
              Re: Apt sources.list Frank <zuiderduin@gmx.com> - 2023-04-16 16:40 +0200
                Re: Apt sources.list John Hasler <john@sugarbit.com> - 2023-04-16 18:20 +0200
          Re: Apt sources.list Frank <zuiderduin@gmx.com> - 2023-04-16 07:20 +0200
            Re: Apt sources.list David Wright <deblis@lionunicorn.co.uk> - 2023-04-16 16:40 +0200
      Re: Apt sources.list <paulf@quillandmouse.com> - 2023-04-15 22:10 +0200
  Re: Apt sources.list Tixy <tixy@yxit.co.uk> - 2023-04-15 18:20 +0200
    Re: Apt sources.list Frank <zuiderduin@gmx.com> - 2023-04-15 22:00 +0200
      Re: Apt sources.list Vincent Lefevre <vincent@vinc17.net> - 2023-04-18 16:40 +0200
        Re: Apt sources.list Frank <zuiderduin@gmx.com> - 2023-04-18 19:50 +0200
          Re: Apt sources.list Jeffrey Walton <noloader@gmail.com> - 2023-04-18 20:00 +0200
            Re: Apt sources.list Vincent Lefevre <vincent@vinc17.net> - 2023-04-20 12:20 +0200
              Re: Apt sources.list Greg Wooledge <greg@wooledge.org> - 2023-04-20 13:30 +0200

csiph-web