Skip to content

Comment on One of the Most Alarming Internet Proposals I've Seen

Comments

It actually appears that the RFC openly admits the potentials for abuse here:

"6. Security Considerations

This document addresses proxies that act as intermediary for HTTP2 traffic and therefore the security and privacy implications of having those proxies in the path need to be considered. MITM [4], [I-D.nottingham-http-proxy-problem] and [I-D.vidya-httpbis-explicit-proxy-ps] discuss various security and privacy issues associated with the use of proxies. Users should be made aware that, different than end-to-end HTTPS, the achievable security level is now also dependent on the security features/capabilities of the proxy as to what cipher suites it supports, which root CA certificates it trusts, how it checks certificate revocation status, etc.

Users should also be made aware that the proxy has visibility to the actual content they exchange with Web servers, including personal and sensitive information."

To play devil's advocate, this could potentially be less harmful than the existing situation: where e.g. various corporate nets will require you to install root certs to accomplish the same MITM attack, in a less visible fashion (after installation), with some if not all of the same caveats - especially if given the ability to opt out.

(Bugs, insufficiently scary UI, and "discovery" are all massive concerns of course...)

various corporate nets will require you to install root certs to accomplish the same MITM attack

They don't even bother making you install CA certificates. They just abuse subordinate CAs: see https://blog.mozilla.org/security/2013/02/15/announcing-vers...

I'm also a huge fan of Google's http://www.certificate-transparency.org/, which makes it very difficult to fool very many people for very long.

Hm, no. Various corporate networks doesn't classify as an ISP, the number of potentially abused users is not the same. A company can do whatever it wants to, an ISP offers a service and should respect the privacy of it's costumers, at least theoretically.

This proposal isn't intended for ISPs and should never be used on the public Internet.

Oh, my bad then. I miss-understood the proposal and it's implications. But since the protocol supports that, how can we be sure that ISPs won't use it?

Cynically, "we can't". Or "they already have better options".

Alternatively, outcry and blacklisting ISP proxies - just as we do with root cert abuse.

Openly admitting the potential for abuse doesn't make this any less ridiculous of a proposal.

I'm not saying it does.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.