Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

This is ridiculous. Wikipedia is headquartered in San Francisco. If the NSA wanted to snoop Wikipedia lookups it would force Wikipedia to install PRISM-like access devices to the site itself, secretly. Switching to HTTPS consumes more resources all around, increases latency, increases site operation costs, and emits more climate changing CO2, with no net change in the NSA's capabilities to snoop Wikipedia lookups.


It's not ridiculous. First, it requires the NSA to actually do what you propose, as opposed to just reading broadly all traffic going through. That is a big difference because it gives the possibility of Wikipedia fighting back. Jimmy Wales has suggested that if he's ever given a FISA gag order, he might disobey it: https://twitter.com/jimmy_wales/status/362596285469044737)


He might disobey a personal gag order, but I can assure you that as long as PRISM exists, U.S. companies will comply if targeted.

There are also plenty of other attack vectors for the NSA even with HTTPS; obtaining the private keys of the common certification authorities is perhaps the most straightforward.


Why would HTTPS necessarily cause more CO2 emissions? Wikipedia might be headquartered in San Francisco, but their data centers are not. For example, their European data center is CO2-neutral. [1]

[1] http://www.thewhir.com/web-hosting-news/evoswitch-hosts-the-...


Their US datacenter is in Florida.

EDIT: My info is out of date. Their Florida datacenter has become the backup, with the primary being Equinix in Ashburn, Virginia:

http://www.datacenterknowledge.com/archives/2013/01/14/its-o...


More computational load = more CO2. Even if they offset CO2 emissions, that money could have been spent more efficiently by not running HTTPS.


NSA isn't the only party interested in wikipedia habbits. Other adversaries in other countries also like to listen.


"If the NSA wanted to snoop Wikipedia lookups it would force Wikipedia to install PRISM-like access devices to the site itself, secretly."

Wikimedia employee here. FYI, we're headquartered in SF, but we have no datacenter here. All traffic goes through our datacenters in FL, VA, and Amsterdam.


So all of your datacenters are in the U.S. and in Holland? State surveillance in the Netherlands is even worse than in the U.S. [1]

[1] http://www.bit-byters.net/2009/11/netherlands-still-1-in-pho...


It may not make much of a difference to you, but I should point out that our colo in the Netherlands is mostly used for a Squid cache cluster, and is not a primary datacenter.

Also, the citation you give is about phone tapping, not the kind of NSA-style online surveillance we're talking about trying to protect against with HTTPS support.

IMO, in general you shouldn't consider your activity over HTTP private regardless of whether you trust a particular government or not. Even some random individual running Firesheep in your local cafe is a threat in such a case.

About the larger point: even with the fully craptastic information we've learned about NSA snooping, there are huge advantages for Wikipedia users to have our organization and Wikipedia data hosted in the United States. As one big one: I'm not sure Wikipedia could survive if it wasn't for Section 230 of the Communications Decency Act.[1]

1. https://www.eff.org/deeplinks/2013/07/cda-230-success-cases-...


The symbol effect is still valuable.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: