Welcome to WebmasterWorld Guest from 54.166.48.3

Forum Moderators: rogerd & travelin cat

Message Too Old, No Replies

WordPress.com to serve all sites via HTTPS

by end of 2014

     
11:57 am on Jun 6, 2014 (gmt 0)

Senior Member from US 

WebmasterWorld Senior Member lorax is a WebmasterWorld Top Contributor of All Time 10+ Year Member Top Contributors Of The Month

joined:Mar 31, 2002
posts:7575
votes: 0


[en.blog.wordpress.com...]

If we've learned anything over the past year, itís that encryption, when done correctly, works. If we properly encrypt our sites and devices, we can make mass surveillance much more difficult.
4:18 pm on June 6, 2014 (gmt 0)

Administrator from US 

WebmasterWorld Administrator incredibill is a WebmasterWorld Top Contributor of All Time 10+ Year Member Top Contributors Of The Month

joined:Jan 25, 2005
posts:14650
votes: 94


we can make mass surveillance much more difficult.


That's true if you made smarter people using the devices that connect to any old open wifi which can easily decrypt SSL using man-in-the-middle attacks. The problem with mobile is due to the smaller interface there's a lot less data available and some things easily spotted and avoided on a desktop have no mobile equivalents so it's easier to be victimized and not know it until it's too late.

Also, while security is great the places already suffering bandwidth issues will feel it just a little more.

All the pings, notifications, pre-fetches and more and more, now using SSL, may look fantastic from a normal broadband connection but you get some sluggish DSL, overloaded or fringe 3G connection, or worse yet the massively overloaded airport wifi and this extra load helps push it over the edge.

P.S. Isn't this a hoot, WP goes "secure" the same day "secure" has a vulnerability, the irony of WP security (oxymoron) just cracks me up:
[webmasterworld.com...]
5:26 pm on June 6, 2014 (gmt 0)

Senior Member from US 

WebmasterWorld Senior Member lorax is a WebmasterWorld Top Contributor of All Time 10+ Year Member Top Contributors Of The Month

joined:Mar 31, 2002
posts:7575
votes: 0


>> Heartbleed

Good point incrediBill. I wonder what their solution will be.
6:41 pm on June 6, 2014 (gmt 0)

Moderator from US 

WebmasterWorld Administrator martinibuster is a WebmasterWorld Top Contributor of All Time 10+ Year Member Top Contributors Of The Month

joined:Apr 13, 2002
posts:14308
votes: 264


Maybe I'm missing something. If the sites hosted on Wordpress.com are public and openly scraped, visited, tweeted and otherwise freely viewed, what is it that is being protected from surveillance?
12:41 am on June 7, 2014 (gmt 0)

Senior Member from US 

WebmasterWorld Senior Member lorax is a WebmasterWorld Top Contributor of All Time 10+ Year Member Top Contributors Of The Month

joined:Mar 31, 2002
posts:7575
votes: 0


I believe it has to do with access to the admin dashboard and the unames/pwds used for access.
2:59 am on June 7, 2014 (gmt 0)

Moderator from US 

WebmasterWorld Administrator martinibuster is a WebmasterWorld Top Contributor of All Time 10+ Year Member Top Contributors Of The Month

joined:Apr 13, 2002
posts:14308
votes: 264


That will help a site from having their passwords sniffed. Not just from government surveillance. Maybe I'm being overly critical or grumpy. Seems a bit exaggerated to posture it as an anti-surveillance thing.
8:52 am on June 7, 2014 (gmt 0)

Administrator from US 

WebmasterWorld Administrator brett_tabke is a WebmasterWorld Top Contributor of All Time 10+ Year Member Top Contributors Of The Month

joined:Sept 21, 1999
posts:38066
votes: 15


Who had a hand in building the security protocols? We are naive if we don't think same ppl can decrypt SSL traffic in real time. SSL = false sense of security.
12:21 pm on June 7, 2014 (gmt 0)

Senior Member from US 

WebmasterWorld Senior Member lorax is a WebmasterWorld Top Contributor of All Time 10+ Year Member Top Contributors Of The Month

joined:Mar 31, 2002
posts:7575
votes: 0


Naw, I don't think you're being overly critical. There seems to be an element of grandstanding involved. There are a few higher priorities on my list for WordPress.