Minichan

Topic: Why does Google hate HTTPS?

Catherine !TGirlYJKXM started this discussion 10 years ago #53,122

I thought HTTPS was suppose to be more secure than HTTP and yet here is Google saying that is a lie.

Nexi !tRAnsGiRLo joined in and replied with this 10 years ago, 2 hours later[^] [v] #693,745

Is the certificate legit? Google doesn't hate HTTPS, Google hates HTTPS that has bad certificates.

Metæ joined in and replied with this 10 years ago, 2 hours later, 4 hours after the original post[^] [v] #693,784

*Bully

r04r joined in and replied with this 10 years ago, 3 hours later, 7 hours after the original post[^] [v] #693,806

dude what

TTEH !PUPenis69. joined in and replied with this 10 years ago, 1 minute later, 7 hours after the original post[^] [v] #693,808

What do you mean?

Fake anon !ZkUt8arUCU joined in and replied with this 10 years ago, 24 minutes later, 8 hours after the original post[^] [v] #693,810

@693,806 (r04r)
@previous (TTEH !PUPenis69.)
Stop trying to avoid the question by asking other irrelevant questions.

Catherine !TGirlYJKXM (OP) replied with this 10 years ago, 16 hours later, 1 day after the original post[^] [v] #693,967

@693,806 (r04r)
@693,808 (TTEH !PUPenis69.)
I think Nexi may have answered my question. I just always notice that Google Chrome seems to always put slashes over "https" and always says it is unsafe. I'm not going to use Tinychan as an example as their certificates always seem to go bad, but it has happened before on sites that I know can be trusted.

r04r replied with this 10 years ago, 3 minutes later, 1 day after the original post[^] [v] #693,969

@previous (Catherine !TGirlYJKXM)
Tinychan recently fixed their SSL certificate and it's green again now. HTTPS is only secure when the certificate can automatically be trusted by your browser. A certificate is what's used to secure the communications between your computer and the server. So you want to know that the certificate your computer is seeing actually belongs to the site. If you use HTTP, anyone that controls the line between you and the site can modify it, these modifications may also include changing the certificate, which would make it invalid. An invalid certificate shows up as red. A valid certificate shows up as green. Certificates have a lifetime of several months to 1-2 years, after this time, they have expired, and become red. A certificate matches a domain name, if it doesn't match, red. A certificate has to be approved (signed) by a so-called certificate authority. These are big companies that are in charge of verifying that the people they give certificates to actually control the domain name listed in the certificates. If any of those conditions are not met, the certificate is invalid, thus red.

So if the certificate is red, most likely is that the site owner put up a bad certificate, or it expired. Or it could mean that someone is eavesdropping on your connection and can see everything that's happening, meaning the security benefit is gone and you might as well be using HTTP hence the red.

Thanks.

(Edited 1 minute later.)

WSD !m2cp3rR5zw joined in and replied with this 10 years ago, 16 minutes later, 1 day after the original post[^] [v] #693,971

yet another brilliant thread by catherine

FuckAlms !vX8K53rFBI joined in and replied with this 10 years ago, 1 day later, 2 days after the original post[^] [v] #694,289

@693,969 (r04r)
Additionally, a certificate can be self-signed by the domain owner if they are cheap and do not wish to pay a certifying authority. These are also valid, however browsers may treat them as invalid.

r04r replied with this 10 years ago, 2 minutes later, 2 days after the original post[^] [v] #694,290

@previous (FuckAlms !vX8K53rFBI)
They are invalid as their validity cannot be confirmed by the browser (the browser cannot tell the difference between a certificate self-signed by the owner, or one self-signed by someone MITMing you). The user could import the site owner's CA certificate to make it valid again. Or the user could manually approve the certificate, but I'm not sure how many browsers support that.

(Edited 7 minutes later.)

beckyderp !Hi.HILLARY joined in and replied with this 10 years ago, 5 hours later, 2 days after the original post[^] [v] #694,370

maagd
:

Please familiarise yourself with the rules and markup syntax before posting.