/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

← → days · ↑ ↓ browse · Enter similar · o open

Should All Web Traffic Be Encrypted?

The prevalence of free, open WiFi has made it rather easy for a WiFi eavesdropper to steal your identity cookie for the websites you visit while you're connected to that WiFi access point.  This is something I talked about in Breaking the Web's Cookie Jar.

Coding Horror Jeff Atwood

Context & Ripple Effects

Jeff Atwood's Coding Horror post picks up a thread he started with his earlier 'Breaking the Web's Cookie Jar' argument: on free, open WiFi, an eavesdropper can lift your identity cookie for any site you visit over plain HTTP and walk straight into your account. The question he poses — should all web traffic be encrypted? — lands two years after Threat Level reported that packet-sniffing laws remained murky even as open hotspots proliferated, meaning the practice was both legally ambiguous and trivially easy.

What makes the moment pointed is that the defense available to ordinary users is essentially nothing: the vulnerability sits in how websites serve sessions, not in anything the person on the coffee-shop AP did wrong. The debate is therefore aimed at site operators and browser vendors, not at hotspot owners.

First-order effects

  • Any site that authenticates users over plain HTTP leaves its session cookies readable to everyone sharing an open access point with the victim — the immediate fix falls on those operators to serve HTTPS sitewide, not just on login pages.
  • Users on public WiFi have no reliable self-protection short of avoiding unencrypted logins entirely, since the theft happens passively on the network.

Second-order effects

  • Widespread default encryption shifts cost and complexity onto certificate authorities and server operators, making cert provisioning and TLS performance central infrastructure questions rather than afterthoughts.
  • Advertising and analytics intermediaries that depend on reading plaintext traffic lose visibility as more sessions move under HTTPS, pressuring their measurement models.

Third-order effects

  • If encryption-by-default becomes the norm, the legal gray zone around packet sniffing documented in 2010 gets resolved de facto by technology rather than by courts — passive interception stops yielding useful data regardless of its legality.
  • The browser vendors and CAs emerge as the de facto trust layer of the web, since they control which certificates and protocols count as secure.

The trend: Open-WiFi cookie theft is one of the forcing functions pushing the web from default-plaintext HTTP toward encryption-by-default, with certificate authorities and browsers setting the pace.