Skip site navigation (1)Skip section navigation (2)
Date:      Mon, 11 Dec 2017 17:40:50 -0500
From:      Yonas Yanfa <yonas@fizk.net>
To:        yuri@rawbw.com
Cc:        freebsd-security@freebsd.org
Subject:   Re: http subversion URLs should be discontinued in favor of https URLs
Message-ID:  <225f2891-dc04-0e38-05bb-b4af9645f663@fizk.net>
In-Reply-To: <201712112129.vBBLT7tj006260@donotpassgo.dyslexicfish.net>
References:  <97f76231-dace-10c4-cab2-08e5e0d792b5@rawbw.com> <2a6d123c-8ee5-8e1e-d99b-4bce02345308@rawbw.com> <1217.1512685566@critter.freebsd.dk> <20171208082503.cve4526nkwf7chef@localhost> <201712112129.vBBLT7tj006260@donotpassgo.dyslexicfish.net>

next in thread | previous in thread | raw e-mail | index | archive | help
On 12/11/2017 16:29, Jamie Landeg-Jones wrote:
> Matthew Finkel <matthew.finkel@gmail.com> wrote:
>
>> Why doesn't everyone have that option? Why is broadcasting a users information
>> across the internet forced upon them? Shouldn't they have a choice?
> They do! HTTPS already exists!
>
> This thread is about removing HTTP and forcing HTTPS - "Why should
> HTTPS be forced upon them? Shouldn't they have a choice?"
>
> :-)
>
>   | 21:16 (4) "/tmp" root@lapcat# svn export https://svn.freebsd.org/base/stable/11/usr.bin/fortune
>   | A    fortune
>   | A    fortune/datfiles
>   |
>   | [ ... ]
>   |
>   | A    fortune/tools/Troff.sed
>   | Exported revision 326782.
>
> Voila! A https delivery of "fortune" ! (Confirmed via tcpdump not to be
> using fallback HTTP)
>
> cheers!

Yuri,

I prefer HTTPS over HTTP as well, but wouldn't switching over to git and 
using signed commits be even more secure than using HTTPS?

Yonas




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?225f2891-dc04-0e38-05bb-b4af9645f663>