From owner-freebsd-security@freebsd.org Mon Dec 11 21:29:09 2017 Return-Path: Delivered-To: freebsd-security@mailman.ysv.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:1900:2254:206a::19:1]) by mailman.ysv.freebsd.org (Postfix) with ESMTP id 65830E9F5D3 for ; Mon, 11 Dec 2017 21:29:09 +0000 (UTC) (envelope-from jamie@catflap.org) Received: from donotpassgo.dyslexicfish.net (donotpassgo.dyslexicfish.net [IPv6:2001:19f0:300:2185:a:dead:bad:faff]) (using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits)) (Client did not present a certificate) by mx1.freebsd.org (Postfix) with ESMTPS id 312787A2E2 for ; Mon, 11 Dec 2017 21:29:09 +0000 (UTC) (envelope-from jamie@catflap.org) Received: from donotpassgo.dyslexicfish.net (donotpassgo.dyslexicfish.net [104.207.135.49]) by donotpassgo.dyslexicfish.net (8.14.5/8.14.5) with ESMTP id vBBLT7sX006261; Mon, 11 Dec 2017 21:29:08 GMT (envelope-from jamie@donotpassgo.dyslexicfish.net) Received: (from jamie@localhost) by donotpassgo.dyslexicfish.net (8.14.5/8.14.5/Submit) id vBBLT7tj006260; Mon, 11 Dec 2017 21:29:07 GMT (envelope-from jamie) From: Jamie Landeg-Jones Message-Id: <201712112129.vBBLT7tj006260@donotpassgo.dyslexicfish.net> Date: Mon, 11 Dec 2017 21:29:07 +0000 Organization: Dyslexic Fish To: phk@phk.freebsd.dk, matthew.finkel@gmail.com Cc: yuri@rawbw.com, freebsd-security@freebsd.org Subject: Re: http subversion URLs should be discontinued in favor of https URLs References: <97f76231-dace-10c4-cab2-08e5e0d792b5@rawbw.com> <2a6d123c-8ee5-8e1e-d99b-4bce02345308@rawbw.com> <1217.1512685566@critter.freebsd.dk> <20171208082503.cve4526nkwf7chef@localhost> In-Reply-To: <20171208082503.cve4526nkwf7chef@localhost> User-Agent: Heirloom mailx 12.4 7/29/08 MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Transfer-Encoding: 7bit X-Greylist: Sender IP whitelisted, not delayed by milter-greylist-4.2.7 (donotpassgo.dyslexicfish.net [104.207.135.49]); Mon, 11 Dec 2017 21:29:08 +0000 (GMT) X-BeenThere: freebsd-security@freebsd.org X-Mailman-Version: 2.1.25 Precedence: list List-Id: "Security issues \[members-only posting\]" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Mon, 11 Dec 2017 21:29:09 -0000 Matthew Finkel wrote: > Why doesn't everyone have that option? Why is broadcasting a users information > across the internet forced upon them? Shouldn't they have a choice? They do! HTTPS already exists! This thread is about removing HTTP and forcing HTTPS - "Why should HTTPS be forced upon them? Shouldn't they have a choice?" :-) | 21:16 (4) "/tmp" root@lapcat# svn export https://svn.freebsd.org/base/stable/11/usr.bin/fortune | A fortune | A fortune/datfiles | | [ ... ] | | A fortune/tools/Troff.sed | Exported revision 326782. Voila! A https delivery of "fortune" ! (Confirmed via tcpdump not to be using fallback HTTP) cheers!