Re: Fwd: [Cryptography] Shaming sites that send sensitive information over HTTP

2014-09-21 Thread coderman
On 9/19/14, staticsafe wrote: > ... > When I go to www.nsa.gov, I do not get a redirect to HTTP. HTTPS with a > cert provided by GeoTrust is what I get. well, at least we know they're listening to customer feedback! ;) [this did indeed change in the interim period, due to server side configur

Re: Fwd: [Cryptography] Shaming sites that send sensitive information over HTTP

2014-09-19 Thread staticsafe
On 9/19/2014 18:58, Peter Gutmann wrote: > grarpamp forwarded: > >> My favorite: The NSA's web site *redirects HTTPS to HTTP*. Some kind of >> back-handed acknowledgement of what they do? > > My guess is that it's politically-motivated, if you're the NSA would you want > to buy your certs from

Re: Fwd: [Cryptography] Shaming sites that send sensitive information over HTTP

2014-09-19 Thread Peter Gutmann
grarpamp forwarded: >My favorite: The NSA's web site *redirects HTTPS to HTTP*. Some kind of >back-handed acknowledgement of what they do? My guess is that it's politically-motivated, if you're the NSA would you want to buy your certs from a commercial CA, and if you're a commercial CA would y

Fwd: [Cryptography] Shaming sites that send sensitive information over HTTP

2014-09-19 Thread grarpamp
-- Forwarded message -- From: Jerry Leichter Date: Fri, Sep 19, 2014 at 12:03 PM To: Cryptography My favorite: The NSA's web site *redirects HTTPS to HTTP*. Some kind of back-handed acknowledgement of what they do? http://httpshaming.tumblr.com