Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

This is probably the best counter-argument to the best counter-argument that gets leveled at the people promoting HTTPS-everywhere. People like to say that HTTPS everywhere would break transparent cacheing by ISPs. After all, HTTP is designed to allow caching proxies to exist inline and still supports dynamic content gracefully (er, somewhat, anyway).

But in fact the same features that make transparent caching easy make this kind of shenanigans easy. There are tons of companies in this space now. Not just people like NebuAd and R66T, but lots of "subscriber messaging systems" like FrontPorch (which I've heard sells messaging data for behavioral advertising) and PerfTech (which has assured me that they do no such thing).

This should be an easy way to push back one of the last "real" arguments against using HTTPS everywhere. There's no excuse not to be running your site on HTTPS all the time - it protects you and your users from all sorts of mischief for a minimal overhead.



It's getting to the stage now where I think domains should be sold with an SSL certificate as standard (minimal vetting, no warranty) - just enough to provide encryption, rather than treating it as an optional extra.


One could argue that DNSSEC is a variant of this - put your SSL certificate in a TXT record in your DNSSEC-signed domain and you no longer need a certificate authority system to sign the certs. Now you can self-sign the cert and get it for free!


If the best argument in favor of HTTPS everywhere is that it will prevent your ISP from showing you ads, the movement is doomed.


The point is not to stop your ISP from showing you ads. The point is to stop your ISP from interfering with your traffic in transit.

If I ran a website with ads, and someone was stripping those ads to replace with their own ads, I'd be annoyed. I'd be amazed if that's something Google would tolerate. We've seen plenty of stories from people saying "Google closed my ad account and froze all my money!!!" so I hope they do that to this ISP and or the company serving the ads.


But you already don't stop your ISP from interfering with your traffic in transit. So why is it a big deal if you continue to not do it? Or is seeing a few ads more important to you than, say, all of your email?


People don't stop their ISPs from tampering because they have a reasonable expectation that the ISP won't tamper.

But, now they've seen their ISP tampering those people might switch on encryption for their email, and everything else.


That's an incredibly naive expectation. ISPs have been replacing error pages with their own search pages serving ads since the 90s.


Ah, yes, you're right. Sorry.

For what it's worth I was grumpy in those situations too. I wrote polite letters. Where possible I opted out.

But your point - this kind of this happens all the time, and has been going on for years, and noone is doing anything to stop it even though it's wrong - is taken.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: