Downloads are no longer available over HTTPS? Topic is solved

About this bulletin board and the Pale Moon website

Moderators: FranklinDM, Lootyhoof

dark_moon

Downloads are no longer available over HTTPS?

Unread post by dark_moon » 2017-05-11, 20:10

I wonder why the Pale Moon downloads on website are no longer available over HTTPS

New Tobin Paradigm

Re: Downloads are no longer available over HTTPS?

Unread post by New Tobin Paradigm » 2017-05-12, 00:23

They never were or should have never been offered via HTTPS.. Doing so for public files adds a lot of overhead and work for the servers. Besides, there are PGP keys and/or SHA256 hashes for you to confirm authenticity. If that isn't enough and the download is suspect you can always ask...

BenFenner
Astronaut
Astronaut
Posts: 588
Joined: 2015-06-01, 12:52
Location: US Southeast

Re: Downloads are no longer available over HTTPS?

Unread post by BenFenner » 2017-05-12, 15:46

Tobin, you're forgetting one of the (main?) benefits of encryption. What about those who want to download the file, and maintain privacy by not announcing to anyone listening that they are downloading said file?

hackerman1
Lunatic
Lunatic
Posts: 385
Joined: 2013-12-19, 15:12
Location: Sweden

Re: Downloads are no longer available over HTTPS?

Unread post by hackerman1 » 2017-05-12, 17:09

Why do you need to hide that you are downloading Pale Moon...? :?
You can use a VPN if you need to hide your traffic.
Administrator on Windows Server to Workstation
Moderator (and "undercover" Admin) on The Windows Club Forum

Security: EAM, Comodo Firewall and HIPS, WinPatrol+, HOSTS-file, UAC (max), Sandboxie, NoScript and ADBlock.

dark_moon

Re: Downloads are no longer available over HTTPS?

Unread post by dark_moon » 2017-05-12, 17:36

I never say i need to hide my traffic.
Even a VPN dont hide your traffic- ist just goes first over the VPN and then to your ISP. Yes, its then encrypted but you need to trust the VPN more then your ISP. Can you that?

Also downloads over HTTPS is for integrity, but the GPG and checksum file over HTTPS is fine.
I thought Pale Moon itself was available over HTTPS. My bad memory... :D

GMforker

Re: Downloads are no longer available over HTTPS?

Unread post by GMforker » 2017-05-12, 18:07

BenFenner wrote:Tobin, you're forgetting one of the (main?) benefits of encryption. What about those who want to download the file, and maintain privacy by not announcing to anyone listening that they are downloading said file?
Because there are different views...
viewtopic.php?f=26&t=8913#p59358
viewtopic.php?f=4&t=14619&p=107592#p104839

User avatar
Moonchild
Pale Moon guru
Pale Moon guru
Posts: 35602
Joined: 2011-08-28, 17:27
Location: Motala, SE
Contact:

Re: Downloads are no longer available over HTTPS?

Unread post by Moonchild » 2017-05-13, 06:19

Downloads have never been available over https, by design.

https exists for security, i.e. secure connections for the transmission of sensitive data, not integrity. Downloading a public binary of Pale Moon is not sensitive data. In-transit tracking of your connections to see what you've downloaded has nothing to do with whether the target site is https or not (and on top, a DNS request for a release mirror host on palemoon.org already gives that away)...

If you don't trust the integrity of what you downloaded, check the SHA-sum, check the cryptographic signatures provided alongside binaries, or check (on windows) the properties of .exe files, tab digital signatures, for the code-signing signatures which also guarantee an untampered binary.
"Sometimes, the best way to get what you want is to be a good person." -- Louis Rossmann
"Seek wisdom, not knowledge. Knowledge is of the past; wisdom is of the future." -- Native American proverb
"Linux makes everything difficult." -- Lyceus Anubite

Locked