Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

HTTPS is a joke #7

Closed
MartinMuzatko opened this issue Mar 4, 2020 · 2 comments
Closed

HTTPS is a joke #7

MartinMuzatko opened this issue Mar 4, 2020 · 2 comments
Assignees
Labels
enhancement New feature or request

Comments

@MartinMuzatko
Copy link

MartinMuzatko commented Mar 4, 2020

I don't see a point using HTTPS everywhere, when I am just consuming content.
And for making transactions, HTTPS is not enough.
You can acquire a certificate easily these days. So many people are happy to sign in to https://paypaI.com (with uppercase i) and give away their credentials, just because it says "secure" . HTTPS doesn't mean the page is secure or not abusing your data for something else. At best it will securely transmit your data to attackers.

I would love to add to this point that HTTPS is a good first step, but it doesn't prevent attackers from getting your data. You need to deliberately inspect what the website is offering and apply common sense. This would be a perfect place to link to the Sensible Computing part.

@MartinMuzatko MartinMuzatko added the enhancement New feature or request label Mar 4, 2020
Lissy93 added a commit that referenced this issue Mar 4, 2020
HTTPS should not be trusted by default. As suggested by @MartinMuzatko in issue #7
@Lissy93
Copy link
Owner

Lissy93 commented Mar 4, 2020

Objectively speaking, not a single one of these steps is enough- it's when they are all used in combination with each other, when you start to strengthen your defences. But I do agree that this should be clearer.

Also your point about HTTPS is very true, and I wouldn't like the reader to get the impression that they can just use HTTPS or something, and then automatically be safe.
So I added an entry into the Sensible Computingsection, in commit f69585e. But feel free to edit it or add anything else in a PR - Cheers for the suggestion 🙌

@Lissy93 Lissy93 closed this as completed Mar 4, 2020
@MartinMuzatko
Copy link
Author

Looks good. Thank you for the addition :)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request
Projects
None yet
Development

No branches or pull requests

2 participants