d2jsp
Log InRegister
d2jsp Forums > d2jsp > Site Suggestions > Site Suggestions Archive >
Poll > An Encrpyted Version Of D2jsp.org > Hypertext Transfer Protocol Secure
Prev12
Closed New Topic New Poll
  Guests cannot view or vote in polls. Please register or login.
Member
Posts: 62,215
Joined: Jun 3 2007
Gold: 9,039.20
Mar 20 2011 10:53pm
http://arstechnica.com/web/news/2011/03/https-is-more-secure-so-why-isnt-the-web-using-it.ars

Excellent article on HTTPS, released about 6 hours from this post.
Member
Posts: 62,215
Joined: Jun 3 2007
Gold: 9,039.20
Mar 23 2011 09:40pm
Also stuff like this: http://www.blyon.com/hey-att-customers-your-facebook-data-went-to-china-and-korea-this-morning/

Though d2jsp isn't near the popularity of Facebook, a simple thing like HTTPS would prevent external and internal sniffing.
Member
Posts: 17,776
Joined: Jan 6 2005
Gold: 19,634.96
Trader: Trusted
Mar 24 2011 03:15am
HTTPS requires heavy server side computation and would likely affect site performance... the SSL encryption algorithms essentially double page load times. Voting No. You shouldn't log on from unsecured locations anyway.

Also, the only thing HTTPS would prevent is cookie jacking on JSP. All credit card transactions etc. are handled by 3rd parties who use encryption. That said, if you get cookie jacked, it's your own damn fault. You shouldn't be browsing from an unsecured wifi network.
Member
Posts: 62,215
Joined: Jun 3 2007
Gold: 9,039.20
Mar 24 2011 02:20pm
Quote (krazi_mofo111 @ Mar 24 2011 03:15am)
HTTPS requires heavy server side computation and would likely affect site performance... the SSL encryption algorithms essentially double page load times. Voting No. You shouldn't log on from unsecured locations anyway.

Also, the only thing HTTPS would prevent is cookie jacking on JSP. All credit card transactions etc. are handled by 3rd parties who use encryption. That said, if you get cookie jacked, it's your own damn fault. You shouldn't be browsing from an unsecured wifi network.


HTTPS should be an option, not necessarily a requirement. I don't believe HTTPS would affect site performance, this isn't the 90's. With the advancements in broadband and browser technology no one with a Cable/Fiber, DSL or mobile broadband connection would notice a difference.

If someone gets cookie jacked it isn't the end users fault, it is the person jacking cookies who is at fault as they are initiating malicious actions. Not everyone has the convenience of being in the comfort of their home every time they are browsing jsp so blaming potential victims because "hackers" exploit their unsecured situation doesn't make sense.

There is no real downside to HTTPS, I don't know how anyone could be against it. The benefits of a secure connection when logging in and making forum gold transactions outweigh any potential performance issues.

Here is a study done comparing the two (HTTP, HTTPS (40 bit) & HTTPS (128 bit): http://www.cs.nyu.edu/artg/research/comparison/comparison_slides/sld017.htm

There is of course cases like these: https://www.eff.org/deeplinks/2011/03/iranian-hackers-obtain-fraudulent-https

This post was edited by killgoreisleet on Mar 24 2011 02:37pm
Admin
Posts: 24,842
Joined: Sep 24 2002
Gold: 40,837.72
Trader: Trusted
Mar 24 2011 02:37pm
Ahh, the illusion of "safety".

http://www.google.com/search?q=how+to+sniff+https+traffic

If you are on a network with other people where they can view your unencrypted traffic, they can also setup tools to view the encrypted traffic. Wireshark and Wiretap both support https sniffing, as well as numerous other tools.

Also, https does significantly increase the amount of bandwidth and server processing power required, all of which, in my opinion, is almost 100% unjustified.

Please note that I am not ruling out using https at some point in the future, but it is an extremely low-priority item for me for the reasons stated above. Thanks
Go Back To Site Suggestions Archive Topic List
Prev12
Closed New Topic New Poll