Certificates are free? Some are. Do you trust certificates given without checking the real identity of the user?
I do not. It has a cost. If you do not check you have the perfect tool for a MITM.
Then is https more expensive than http?
Of course you idiot. Have you never seen your CPU burn under https? With TLS the load is on the first connection. Meaning it is around x% (x said to be 1 by google) for long sessions IF and only IF you have a costly engineer optimizing your stack. And I know by experience that google cipher suite are sometimes close to be ridicusly weak in order to achieve this. (I saw an RC4 while playing with gmail). And that is servers side. Add the client side.
So what about no "engineer". What about an SSL2.0 cipher suite having RC4 MD5 ... and all the default weak settings recommended you can see on the internet?
Well, the illusion of security is no security. the S of https is for security. Having a tag saying I am secure if any government or criminal organisation can break your ciphering in a matter of seconds is no actual security. And it defeats the purpose of TRUST granted by security.
Then way pay the extra x% of https in this case?
Oh! I just read your last paragraph.
Can someone explain to this person why HTTPS cannot be cached?
Oh! It can it : has been sold to Tunisia by MS in 2007, France to lybia circa 2005, China is doing it ... for intercepting and deciphering citizens conversation.
Caching HTTPS is basically doing a Man In The Middle attack. It requires a "joker" certificate nicely given by a root authority. Doing so (as microsoft did) normaly induce "the death penalty" of security firms. MS is alive, hence anyway we cannot trust https ... since snowden revelations.
The proxy would still have to do the handshake anyway to have the https => cpu load.
The premise of security are trust. https nowadays is a costly joke.
For the record operators especially when IP routing goes through shared tunnel of collects (3G) have been traditionnaly using a protocol called WCCP to cache transparently your http content. And 4G is deployed substantially in USA & wealthy European countries, but not everywhere.
So even if you don't have a proxy your operator may.
Last and least : I worked in an ISP 10 years ago. One of the datacenter was 5% of france global traffic, the electricity used was as much as a city of 40K inhabitants.
It makes internet as an industry the biggest user of fossil energies. According to my approximation we should be around 2%[+1%?] of the global national consumption. Very near transport industry (plane + trucks). And https will not help.
So I see no other arguments for https than being sheeps.
> Certificates are free? Some are. Do you trust certificates given without checking the real identity of the user? I do not. It has a cost. If you do not check you have the perfect tool for a MITM.
But you just said that HTTP was fine, right? You can MITM plaintext HTTP too, so I don't understand why that's a problem for HTTPS to be (potentially) MITMable.
I do not. It has a cost. If you do not check you have the perfect tool for a MITM.
Then is https more expensive than http?
Of course you idiot. Have you never seen your CPU burn under https? With TLS the load is on the first connection. Meaning it is around x% (x said to be 1 by google) for long sessions IF and only IF you have a costly engineer optimizing your stack. And I know by experience that google cipher suite are sometimes close to be ridicusly weak in order to achieve this. (I saw an RC4 while playing with gmail). And that is servers side. Add the client side.
So what about no "engineer". What about an SSL2.0 cipher suite having RC4 MD5 ... and all the default weak settings recommended you can see on the internet?
Well, the illusion of security is no security. the S of https is for security. Having a tag saying I am secure if any government or criminal organisation can break your ciphering in a matter of seconds is no actual security. And it defeats the purpose of TRUST granted by security.
Then way pay the extra x% of https in this case?
Oh! I just read your last paragraph.
Can someone explain to this person why HTTPS cannot be cached? Oh! It can it : has been sold to Tunisia by MS in 2007, France to lybia circa 2005, China is doing it ... for intercepting and deciphering citizens conversation.
Caching HTTPS is basically doing a Man In The Middle attack. It requires a "joker" certificate nicely given by a root authority. Doing so (as microsoft did) normaly induce "the death penalty" of security firms. MS is alive, hence anyway we cannot trust https ... since snowden revelations.
The proxy would still have to do the handshake anyway to have the https => cpu load.
The premise of security are trust. https nowadays is a costly joke.
For the record operators especially when IP routing goes through shared tunnel of collects (3G) have been traditionnaly using a protocol called WCCP to cache transparently your http content. And 4G is deployed substantially in USA & wealthy European countries, but not everywhere.
So even if you don't have a proxy your operator may.
And if you think all USA is at 1Mb/sec for 50$/months read this http://seclists.org/nanog/2015/Oct/337
Last and least : I worked in an ISP 10 years ago. One of the datacenter was 5% of france global traffic, the electricity used was as much as a city of 40K inhabitants.
It makes internet as an industry the biggest user of fossil energies. According to my approximation we should be around 2%[+1%?] of the global national consumption. Very near transport industry (plane + trucks). And https will not help.
So I see no other arguments for https than being sheeps.