Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> Are those the main threats?

Maybe? Your threat model may vary. If you're very focused on happy news, most people's network use is not tampered with in a way that directly interferes with their enjoyment most of the time. If that's really all you wanted then you can reason TLS is unnecessary for you†

If the coffee shop uses WPA3 and not any older version (do you check?) and if you have your own secret password for the coffee shop WiFi not shared with anybody else (do you?) then WPA3 means crab probably cannot impersonate your coffee shop's WiFi router by hanging out in the coffee shop, although there are plenty of problems in practice with WPA3 implementations.

But what if crab runs the coffee shop WiFi anyway? Do you interview coffee shop owners about who provides their WiFi? It's just a cheap way to keep customers in the shop (if it's the sort of coffee shop that wants to do that) and who provides it and why isn't top of the owner's mind.

Maybe the family owned coffee shop just uses the stock ISP WiFi router and they're paying $50 per month like everybody else in the neighbourhood for Internet access. But, is that ISP the most scrupulous business? They can make money if they inject advertisements into your browsing, or if they can at least associate your address to specific browsing activity so that can be monetized. Perhaps even if the ISP itself is high-minded enough to turn these opportunities down an individual ISP employee is not, network engineers can certainly choose to eavesdrop easily enough.

† But you aren't using TLS just for you. We must all hang together or most assuredly we shall all hang separately. If only a relative minority of people use protocols which provide them with features like confidentiality, those people stand out more easily to be attacked. Don't Stand Out is an increasingly important property to protect us all by sheer numbers.



> most people's network use is not tampered with in a way that directly interferes with their enjoyment most of the time. If that's really all you wanted then you can reason TLS is unnecessary for you

I would go beyond that and say that the reason most networks people use do not tamper with the traffic is because most people use TLS nowadays. Not too long ago, it was very common for networks to use a "transparent HTTP proxy", intercepting all TCP port 80 traffic and redirecting it to a separate box with a caching HTTP proxy like Squid, in an attempt to reduce the traffic. This sucked whenever the HTTP proxy misbehaved (which was not uncommon; many operators seemed to configure it to cache more than it should). Since nowadays most HTTP traffic is protected by TLS, transparent caching HTTP proxies no longer provide a relevant reduction in the bandwidth use, and so they became less common.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: