Should All Web Traffic Be Encrypted?
The prevalence of free, open WiFi has made it rather easy for a WiFi eavesdropper to steal your identity cookie for the websites you visit while you're connected to that WiFi access point. This is something I talked about in Breaking the Web's Cookie Jar.
Context & Ripple Effects
Jeff Atwood's Coding Horror post picks up a thread he started with his earlier 'Breaking the Web's Cookie Jar' argument: on free, open WiFi, an eavesdropper can lift your identity cookie for any site you visit over plain HTTP and walk straight into your account. The question he poses — should all web traffic be encrypted? — lands two years after Threat Level reported that packet-sniffing laws remained murky even as open hotspots proliferated, meaning the practice was both legally ambiguous and trivially easy.
What makes the moment pointed is that the defense available to ordinary users is essentially nothing: the vulnerability sits in how websites serve sessions, not in anything the person on the coffee-shop AP did wrong. The debate is therefore aimed at site operators and browser vendors, not at hotspot owners.
First-order effects
- Any site that authenticates users over plain HTTP leaves its session cookies readable to everyone sharing an open access point with the victim — the immediate fix falls on those operators to serve HTTPS sitewide, not just on login pages.
- Users on public WiFi have no reliable self-protection short of avoiding unencrypted logins entirely, since the theft happens passively on the network.
Second-order effects
- Widespread default encryption shifts cost and complexity onto certificate authorities and server operators, making cert provisioning and TLS performance central infrastructure questions rather than afterthoughts.
- Advertising and analytics intermediaries that depend on reading plaintext traffic lose visibility as more sessions move under HTTPS, pressuring their measurement models.
Third-order effects
- If encryption-by-default becomes the norm, the legal gray zone around packet sniffing documented in 2010 gets resolved de facto by technology rather than by courts — passive interception stops yielding useful data regardless of its legality.
- The browser vendors and CAs emerge as the de facto trust layer of the web, since they control which certificates and protocols count as secure.
The trend: Open-WiFi cookie theft is one of the forcing functions pushing the web from default-plaintext HTTP toward encryption-by-default, with certificate authorities and browsers setting the pace.