/Cinny
@IngaLovinde @mjg59 @sodiboo basically: you encrypt your traffic because you can’t prove that someone could be sniffing it
browsers encrypt their traffic because they also can’t prove that someone could be sniffing it
the threat model is kind of very similar, it’s just that in rare circumstances they might overlap
/Cinny
Web browsers are built around their own threat model, if you need something different you need to look elsewhere. that doesn’t make it “emotional support crypto” ever
hell if you encrypt your transport traffic and nobody sniffs it, isn’t that also basically unnecessary in that regard?
or is it just a problem when the protections against threat model A overlap the encrypted transport that you have very unexpectedly applied to a very small amount of destinations?
/Cinny
@sodiboo @IngaLovinde @mjg59 browsers don’t fully prevent access to http websites that is true
they do offer ways to block http or mixed access, they restrict features on insecure origin, they are also either optionally or unconditionally redirecting to HTTPS. Browsers warn users about entering personal details on insecure pages, about even opening them (not usually by default). personally i think the restrictions do not go far enough but that’s where pragmatism throws a wrench into things
/Cinny
also as a related question: should a browser consider the gateway ip on an encrypted wifi network to be a secure origin?
/Cinny
@sodiboo @IngaLovinde @mjg59 the particular threat model on the server side is different: you know as the admin that the transport is encrypted. you can safely make the assumption that all traffic from wireguard peer ips is from an authorized host, as such your threat model would more be compromise of the peer and not that the network can be spied out by a man in the middle
but you then connect the two threat models together, the stronger one wins by default
you are of course free to not use a web browser (or modify it to meet your weaker threat model!) but the web browser threat model being stronger doesn’t make it emotional support cryptography
/Cinny
@sodiboo @IngaLovinde @mjg59 the browser’s threat model is “the transport is unsafe and can be intercepted and read out and maybe even modified” and localhost traffic is the sole exception that you can know as a browser. there is no way for a browser to determine whether a path has some other encryption applied, an even if it were possible whether it could be intercepted by someone unauthorized. specific niche setups that do not apply to most web access for most users do not get considered because you cannot safely assume that any non-localhost traffic is encrypted
/Cinny
me when I forget to set my post visibility to followers only
/Cinny
one of these days there is a real legit emergency alert and the fedi creatures are too busy WEEWOOing on fedi to seek shelter
/Cinny
I’ve managed to be in the Netherlands during the German weewoo and in Germany during the Dutch weewoo
/Cinny
/Cinny
neiiin charlie kirk du musst die warntag app installieren!!! charlie hoert die warnung nicht er hat airpods drinne oh nein gleich wird er erschossen ohje nein jetzt haben sie charlie kirk erschossen weil er nicht das weewoo gehoert hat