{"id":12057,"date":"2009-01-23T11:44:00","date_gmt":"2009-01-23T11:44:00","guid":{"rendered":"https:\/\/masabidev.wpengine.com\/news\/how-do-transcoders-affect-https\/"},"modified":"2014-11-25T15:22:48","modified_gmt":"2014-11-25T15:22:48","slug":"how-do-transcoders-affect-https","status":"publish","type":"post","link":"https:\/\/www.masabi.com\/es\/news\/how-do-transcoders-affect-https\/","title":{"rendered":"How Do Transcoders Affect HTTPS?"},"content":{"rendered":"<div class=\"block-\">After reading the interesting discussion about mobile transcoders and HTTPS security on the <a href=\"https:\/\/tech.groups.yahoo.com\/group\/momolondon\/message\/6021\">MoMo London mailing list<\/a> (may require sign-in), based on some <a href=\"https:\/\/lists.w3.org\/Archives\/Public\/public-bpwg\/2009Jan\/\">related discussion<\/a> around the new W3C guidelines for transcoding, I thought there was some value in a blog post which explains the issues from more of a layman\u2019s perspective.<\/p>\n<p>First up \u2013 transcoders are servers which sit between a mobile phone and a web site, and reformat the web site to (hopefully) make it easier to navigate and use on a handset.  A number of operators have installed them, and their customers generally not aware of this \u2013 hopefully they just receive a better user experience. This is a subject with a <a href=\"https:\/\/mobiforge.com\/developing\/blog\/teliasonera-launching-novarra-transcoder-updated\">chequered past<\/a>, that arouses considerable passion among those <a href=\"https:\/\/news.zdnet.co.uk\/communications\/0,1000000085,39287413,00.htm\">for<\/a> and <a href=\"https:\/\/wurfl.sourceforge.net\/vodafonerant\/\">against<\/a> \u2013 I\u2019ll take a neutral stance in this blog post and purely discuss the security implications of what is going on!<\/p>\n<p>In a conventional <a href=\"https:\/\/en.wikipedia.org\/wiki\/Https\">HTTPS connection<\/a>, as made by a desktop browser, the browser makes an \u201cunbreakable\u201d connection directly to the web site you are accessing &#8211; anyone between you and the site can view the bytes passing between the two, but cannot understand what they mean.  <span style=\"font-style: italic;\">Note that, for our purposes here, an \u201cunbreakable\u201d connection is one which is impractical to break within weeks using currently available technology assuming no compromise of the server\u2019s private key \u2013 in reality nothing is completely unbreakable!<\/span>  The same should hold true for an HTTPS Wap2 connection between a phone and a web site, without any transcoders:<\/p>\n<p style=\"text-align:center\"><img decoding=\"async\" src=\"http:\/\/localhost:10003\/blogContent\/wap2.gif\" title=\"Wap2 end to end HTTPS connection\" \/><\/p>\n<p>If you double click on the little padlock on your browser when accessing a site over HTTPS, you&#8217;ll see a certificate from a trusted certificate issuer (eg. Verisign) stating which domain you have the end-to-end connection with:<\/p>\n<p style=\"text-align:center\"><img decoding=\"async\" src=\"http:\/\/localhost:10003\/blogContent\/sslCert.jpg\" title=\"Viewing an SSL certificate from a web browser\" \/><\/p>\n<p>On phones, you should be able to do the same thing through the menu system \u2013 here\u2019s one on Nokia S40:<\/p>\n<p style=\"text-align:center\"><img decoding=\"async\" src=\"http:\/\/localhost:10003\/blogContent\/s40certAmazon.gif\" title=\"Viewing Amazon's SSL certificate in S40's browser\" \/><\/p>\n<p>Alarmingly, on this same Nokia S40 browser, the Organisational Unit label of the certificate is displayed <i>instead of<\/i> the Organisation name if both are specified, which often has no meaning to the user.  For example Barclays Bank does an excellent impression of being a fake certificate to users not in the know:<\/p>\n<p style=\"text-align:center\"><img decoding=\"async\" src=\"http:\/\/localhost:10003\/blogContent\/s40certBarclays.gif\" title=\"Viewing Barclay's SSL certificate in S40's browser\" \/><\/p>\n<p>However, in principle and when well implemented, the certificate system allows users to trust they are talking to the correct server with some rigorous maths in the background confirming everything.  Desktop browsers are increasingly finding ways to automate additional certificate checks and <a href=\"https:\/\/blogs.msdn.com\/ie\/archive\/2005\/11\/21\/495507.aspx\">flag up anything unusual<\/a>, and the mobile web (with its more fiddly certificate checking) will doubtless follow along slowly.<\/p>\n<p>It is worth noting that older Wap1 \u201csecure\u201d connections were not really secure.  The handset communicated to the operator\u2019s gateway over a WLTS connection, which was allowed in most cases to use lower key strengths and weaker algorithms which could be broken more easily.  The gateway server on the edge of the operator\u2019s network would then decrypt the information and send it on to the end web server over a true HTTPS connection.  There were therefore two weaknesses &#8211; interception between handset and gateway, and hacking of the gateway to view the connection in plaintext:<\/p>\n<p style=\"text-align:center\"><img decoding=\"async\" src=\"http:\/\/localhost:10003\/blogContent\/wap1.gif\" title=\"Wap1 WTLS is decoded at the gateway\" \/><\/p>\n<p>These days almost all handsets use <a href=\"https:\/\/www.informit.com\/articles\/article.aspx?p=23999&amp;seqNum=4\">Wap2<\/a> \u2013 which allows for true end-to-end HTTPS.  However, as an aside you can easily skip \u2013 and here I hold my hands up and declare I know nothing definitively \u2013 it is ambiguous what happens when a Wap2 handset connects using Wap network settings.  Wap2 is allowed to work just like Wap1 through a gateway, but also prefers end-to-end TCP\/IP that is bridged through the gateway but does not need extra translation done there, conventionally configured using \u201cInternet\u201d network settings on the handset.  Most operators also provision \u201cWap\u201d settings on handsets, which were traditionally used to connect an old Wap1 browser to the gateway using a different protocol which emulated some aspects of normal web protocols.  When a Wap2 browser (that is also able to handle Wap1, as most are) tries to connect to a server over HTTPS through a Wap connection, is it using weak WTLS to the gateway as in an old Wap1 connection, or is it still using a true HTTPS connection?  I am not certain of the answer, and I imagine it would depend on the handset model, browser software and network\u2019s setup (as some gateways can auto-switch between both transparently) so it is difficult to test definitively.  If anyone knows please clarify in the comments!<\/p>\n<p>Back to transcoders.  The controversial aspect is the way that a transcoder inserts itself into this secure connection in order to \u201cimprove\u201d the page markup (I\u2019ll leave the argument about whether transcoders do or don&#8217;t improve the markup to others).  The transcoder forces the browser to make its secure connection to the transcoder, which then makes a subsequent onward connection to the real web server \u2013 a model which looks remarkably like Wap1, with better security between handset and intermediary:<\/p>\n<p style=\"text-align:center\"><img decoding=\"async\" src=\"http:\/\/localhost:10003\/blogContent\/transcoder.gif\" title=\"Transcoder sitting between handset and server\" \/><\/p>\n<p>Click on that browser padlock while using this scenario, and you would see the transcoder\u2019s certificate and not the certificate of the site you are connecting to.  The end result is: whereas in a conventional HTTPS connection, you only share your private information with the site you have chosen, in the transcoding case you share it with the target site and any employee of the transcoder company who has access to the transcoding servers, plus anyone who has hacked the transcoder server.<br \/>In reality, any responsible transcoder company would operate their servers with <a href=\"https:\/\/www.pcisecuritystandards.org\/\" title=\"Payment Card Industry Data Security Standard\">PCI-DSS compliance<\/a> (the standard required of any company which takes credit card payments), and this would be a minimal risk, but it is more risk than if they weren\u2019t in the loop.<\/p>\n<p>I have discussed this with <a href=\"https:\/\/www.novarra.com\/\">Novarra<\/a> (who run Vodafone\u2019s transcoder service in the UK) and they confirmed that they do operate their servers to these standards, but I haven\u2019t talked to any others \u2013 and I think some of the concern people feel is that this is not an opt-in service, it is something done to your \u201csecure\u201d connection without your knowledge.<br \/>As an aside, Opera have long operated this sort of system with their Mini browser, and <a href=\"https:\/\/www.opera.com\/mini\/help\/faq\/#security\">their FAQ<\/a> makes it clear that you should not use the browser for any confidential connections such as accessing your bank \u2013 however Barclays Bank, for example, have <a href=\"https:\/\/www.barclays.mobi\/\">long recommended Opera Mini<\/a> for customers wishing to access their accounts on a mobile (recently they have added a disclaimer stating they have no responsibility if you do this):<\/p>\n<p style=\"text-align:center\"><img decoding=\"async\" src=\"http:\/\/localhost:10003\/blogContent\/barclaysOperaConditions.gif\" title=\"Barclays.mobi and Opera Mini FAQ\" \/><\/p>\n<p>There is a second problem with any system \u2013 Wap1 or transcoders \u2013 that obscures the certificate of the end web server.  One of the key advantages of HTTPS is that, by providing end-to-end security and trusted certificates, you always know who you are talking to.  A major class of attack is the \u201cman in the middle\u201d attack, where a server sits between your browser and the end site and takes a copy of all confidential information passing between them.  If a server tried to do this with a true HTTPS connection you would be able to tell, because the certificate you saw would not match the server you thought you were connecting to:<\/p>\n<p style=\"text-align:center\"><img decoding=\"async\" src=\"http:\/\/localhost:10003\/blogContent\/wap2cert.gif\" title=\"Confirming the end certificate in Wap2\" \/><\/p>\n<p>If there was a thief\u2019s server pretending to be the web server, it would not have the correct certificate and you could tell an attack was taking place:<\/p>\n<p style=\"text-align:center\"><img decoding=\"async\" src=\"http:\/\/localhost:10003\/blogContent\/manInMiddle.gif\" title=\"Standard man in the middle attack\" \/><\/p>\n<p>A transcoder in the middle prevents this, because the end user only ever sees the transcoder\u2019s certificate \u2013 the end web server\u2019s certificate is only seen by the transcoder.  As the user knows nothing about the features of the transcoding software, and the specific deployment configuration of that transcoder on their operator, they cannot tell whether the transcoder has been implemented to correctly verify the end certificate against what the user was expecting:<\/p>\n<p style=\"text-align:center\"><img decoding=\"async\" src=\"http:\/\/localhost:10003\/blogContent\/transcoderCert.gif\" title=\"Transcoder obscuring end certificate\" \/><\/p>\n<p>A thief could easily sit on the other side of the transcoder, and the user would know no better:<\/p>\n<p style=\"text-align:center\"><img decoding=\"async\" src=\"http:\/\/localhost:10003\/blogContent\/transcoderThief.gif\" title=\"Transcoder obscuring thief's certificate\" \/><\/p>\n<p>This is clearly a retrograde step \u2013 moving back towards the insecurity and uncertainty of Wap1.  The worry is, if breaking HTTPS security becomes \u00aballowable\u00bb, we are setting a very worrying precedent for trust in HTTPS and the security of mobile web commerce in the future. History shows that thieves and hackers are becoming rapidly more sophisticated with no signs of stopping \u2013 it is difficult to argue that, under those circumstances, we should make things easier for them.<\/p>\n<p>Transcoding servers may take steps to confirm the identity of downstream web server&#8217;s certificates, and they may not (I am waiting for some confirmation on this from Novarra, for example, and will update the post if and when they provide it).  They may prevent the user from accessing sites which have incorrect certificates, or allow the user to choose whether to continue.  They may have the ability to do this but allow operators to make these policy decisions, who may not understand the implications.  Already we know that some transcoders will not break HTTPS for some banks, but that would be no consolation to a corporate IT department who may unwittingly open up a potential hole in their corporate network, for example.<\/p>\n<p>This is a company blog so I have to mention &#8211; the lack of certainty and lack of security on mobile was a key motivator behind Masabi\u2019s creation of <a href=\"http:\/\/localhost:10003\/tech_encryptME.html\">EncryptME<\/a>, which powers our secure applications.  We always provide our own full end-to-end security to wrap up transactions, either over the top of SMS or HTTP, giving true desktop-strength security from the mobile, regardless of what the operator or transcoder attempts to do in the middle.  Because we understand security and have complete control over application workflow, we also know when to use more than just end-to-end encryption, which is a component of system security but never in itself a guarantor of full security.<\/div>\n","protected":false},"excerpt":{"rendered":"<p>After reading the interesting discussion about mobile transcoders and HTTPS security on the MoMo London mailing list (may require sign-in), based on some related discussion around the new W3C guidelines for transcoding, I thought there was some value in a blog post which explains the issues from more of a layman\u2019s perspective. First up \u2013 [&hellip;]<\/p>\n","protected":false},"author":22,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[],"tags":[],"class_list":["post-12057","post","type-post","status-publish","format-standard","hentry"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.6 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>How Do Transcoders Affect HTTPS? - Masabi<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.masabi.com\/es\/news\/how-do-transcoders-affect-https\/\" \/>\n<meta property=\"og:locale\" content=\"es_ES\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"How Do Transcoders Affect HTTPS? - Masabi\" \/>\n<meta property=\"og:description\" content=\"After reading the interesting discussion about mobile transcoders and HTTPS security on the MoMo London mailing list (may require sign-in), based on some related discussion around the new W3C guidelines for transcoding, I thought there was some value in a blog post which explains the issues from more of a layman\u2019s perspective. First up \u2013 [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.masabi.com\/es\/news\/how-do-transcoders-affect-https\/\" \/>\n<meta property=\"og:site_name\" content=\"Masabi\" \/>\n<meta property=\"article:published_time\" content=\"2009-01-23T11:44:00+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2014-11-25T15:22:48+00:00\" \/>\n<meta property=\"og:image\" content=\"http:\/\/localhost:10003\/blogContent\/wap2.gif\" \/>\n<meta name=\"author\" content=\"Tom Godber\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Escrito por\" \/>\n\t<meta name=\"twitter:data1\" content=\"Tom Godber\" \/>\n\t<meta name=\"twitter:label2\" content=\"Tiempo de lectura\" \/>\n\t<meta name=\"twitter:data2\" content=\"8 minutos\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.masabi.com\\\/es\\\/news\\\/how-do-transcoders-affect-https\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.masabi.com\\\/es\\\/news\\\/how-do-transcoders-affect-https\\\/\"},\"author\":{\"name\":\"Tom Godber\",\"@id\":\"https:\\\/\\\/www.masabi.com\\\/es\\\/#\\\/schema\\\/person\\\/03ddc0b4368069eb9e5a9e9d9d17e97c\"},\"headline\":\"How Do Transcoders Affect HTTPS?\",\"datePublished\":\"2009-01-23T11:44:00+00:00\",\"dateModified\":\"2014-11-25T15:22:48+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.masabi.com\\\/es\\\/news\\\/how-do-transcoders-affect-https\\\/\"},\"wordCount\":1631,\"image\":{\"@id\":\"https:\\\/\\\/www.masabi.com\\\/es\\\/news\\\/how-do-transcoders-affect-https\\\/#primaryimage\"},\"thumbnailUrl\":\"http:\\\/\\\/localhost:10003\\\/blogContent\\\/wap2.gif\",\"inLanguage\":\"es\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.masabi.com\\\/es\\\/news\\\/how-do-transcoders-affect-https\\\/\",\"url\":\"https:\\\/\\\/www.masabi.com\\\/es\\\/news\\\/how-do-transcoders-affect-https\\\/\",\"name\":\"How Do Transcoders Affect HTTPS? - Masabi\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.masabi.com\\\/es\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.masabi.com\\\/es\\\/news\\\/how-do-transcoders-affect-https\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.masabi.com\\\/es\\\/news\\\/how-do-transcoders-affect-https\\\/#primaryimage\"},\"thumbnailUrl\":\"http:\\\/\\\/localhost:10003\\\/blogContent\\\/wap2.gif\",\"datePublished\":\"2009-01-23T11:44:00+00:00\",\"dateModified\":\"2014-11-25T15:22:48+00:00\",\"author\":{\"@id\":\"https:\\\/\\\/www.masabi.com\\\/es\\\/#\\\/schema\\\/person\\\/03ddc0b4368069eb9e5a9e9d9d17e97c\"},\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.masabi.com\\\/es\\\/news\\\/how-do-transcoders-affect-https\\\/#breadcrumb\"},\"inLanguage\":\"es\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.masabi.com\\\/es\\\/news\\\/how-do-transcoders-affect-https\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/www.masabi.com\\\/es\\\/news\\\/how-do-transcoders-affect-https\\\/#primaryimage\",\"url\":\"http:\\\/\\\/localhost:10003\\\/blogContent\\\/wap2.gif\",\"contentUrl\":\"http:\\\/\\\/localhost:10003\\\/blogContent\\\/wap2.gif\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.masabi.com\\\/es\\\/news\\\/how-do-transcoders-affect-https\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.masabi.com\\\/es\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"How Do Transcoders Affect HTTPS?\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.masabi.com\\\/es\\\/#website\",\"url\":\"https:\\\/\\\/www.masabi.com\\\/es\\\/\",\"name\":\"Masabi\",\"description\":\"Making shared transport the first choice\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.masabi.com\\\/es\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"es\"},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.masabi.com\\\/es\\\/#\\\/schema\\\/person\\\/03ddc0b4368069eb9e5a9e9d9d17e97c\",\"name\":\"Tom Godber\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/4db29d09205fdf139cd15ed5d9b41dff69022faa7d603eed888ea6d0bfc8fe81?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/4db29d09205fdf139cd15ed5d9b41dff69022faa7d603eed888ea6d0bfc8fe81?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/4db29d09205fdf139cd15ed5d9b41dff69022faa7d603eed888ea6d0bfc8fe81?s=96&d=mm&r=g\",\"caption\":\"Tom Godber\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"How Do Transcoders Affect HTTPS? - Masabi","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.masabi.com\/es\/news\/how-do-transcoders-affect-https\/","og_locale":"es_ES","og_type":"article","og_title":"How Do Transcoders Affect HTTPS? - Masabi","og_description":"After reading the interesting discussion about mobile transcoders and HTTPS security on the MoMo London mailing list (may require sign-in), based on some related discussion around the new W3C guidelines for transcoding, I thought there was some value in a blog post which explains the issues from more of a layman\u2019s perspective. First up \u2013 [&hellip;]","og_url":"https:\/\/www.masabi.com\/es\/news\/how-do-transcoders-affect-https\/","og_site_name":"Masabi","article_published_time":"2009-01-23T11:44:00+00:00","article_modified_time":"2014-11-25T15:22:48+00:00","og_image":[{"url":"http:\/\/localhost:10003\/blogContent\/wap2.gif","type":"","width":"","height":""}],"author":"Tom Godber","twitter_card":"summary_large_image","twitter_misc":{"Escrito por":"Tom Godber","Tiempo de lectura":"8 minutos"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.masabi.com\/es\/news\/how-do-transcoders-affect-https\/#article","isPartOf":{"@id":"https:\/\/www.masabi.com\/es\/news\/how-do-transcoders-affect-https\/"},"author":{"name":"Tom Godber","@id":"https:\/\/www.masabi.com\/es\/#\/schema\/person\/03ddc0b4368069eb9e5a9e9d9d17e97c"},"headline":"How Do Transcoders Affect HTTPS?","datePublished":"2009-01-23T11:44:00+00:00","dateModified":"2014-11-25T15:22:48+00:00","mainEntityOfPage":{"@id":"https:\/\/www.masabi.com\/es\/news\/how-do-transcoders-affect-https\/"},"wordCount":1631,"image":{"@id":"https:\/\/www.masabi.com\/es\/news\/how-do-transcoders-affect-https\/#primaryimage"},"thumbnailUrl":"http:\/\/localhost:10003\/blogContent\/wap2.gif","inLanguage":"es"},{"@type":"WebPage","@id":"https:\/\/www.masabi.com\/es\/news\/how-do-transcoders-affect-https\/","url":"https:\/\/www.masabi.com\/es\/news\/how-do-transcoders-affect-https\/","name":"How Do Transcoders Affect HTTPS? - Masabi","isPartOf":{"@id":"https:\/\/www.masabi.com\/es\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.masabi.com\/es\/news\/how-do-transcoders-affect-https\/#primaryimage"},"image":{"@id":"https:\/\/www.masabi.com\/es\/news\/how-do-transcoders-affect-https\/#primaryimage"},"thumbnailUrl":"http:\/\/localhost:10003\/blogContent\/wap2.gif","datePublished":"2009-01-23T11:44:00+00:00","dateModified":"2014-11-25T15:22:48+00:00","author":{"@id":"https:\/\/www.masabi.com\/es\/#\/schema\/person\/03ddc0b4368069eb9e5a9e9d9d17e97c"},"breadcrumb":{"@id":"https:\/\/www.masabi.com\/es\/news\/how-do-transcoders-affect-https\/#breadcrumb"},"inLanguage":"es","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.masabi.com\/es\/news\/how-do-transcoders-affect-https\/"]}]},{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/www.masabi.com\/es\/news\/how-do-transcoders-affect-https\/#primaryimage","url":"http:\/\/localhost:10003\/blogContent\/wap2.gif","contentUrl":"http:\/\/localhost:10003\/blogContent\/wap2.gif"},{"@type":"BreadcrumbList","@id":"https:\/\/www.masabi.com\/es\/news\/how-do-transcoders-affect-https\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.masabi.com\/es\/"},{"@type":"ListItem","position":2,"name":"How Do Transcoders Affect HTTPS?"}]},{"@type":"WebSite","@id":"https:\/\/www.masabi.com\/es\/#website","url":"https:\/\/www.masabi.com\/es\/","name":"Masabi","description":"Making shared transport the first choice","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.masabi.com\/es\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"es"},{"@type":"Person","@id":"https:\/\/www.masabi.com\/es\/#\/schema\/person\/03ddc0b4368069eb9e5a9e9d9d17e97c","name":"Tom Godber","image":{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/secure.gravatar.com\/avatar\/4db29d09205fdf139cd15ed5d9b41dff69022faa7d603eed888ea6d0bfc8fe81?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/4db29d09205fdf139cd15ed5d9b41dff69022faa7d603eed888ea6d0bfc8fe81?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/4db29d09205fdf139cd15ed5d9b41dff69022faa7d603eed888ea6d0bfc8fe81?s=96&d=mm&r=g","caption":"Tom Godber"}}]}},"_links":{"self":[{"href":"https:\/\/www.masabi.com\/es\/wp-json\/wp\/v2\/posts\/12057","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.masabi.com\/es\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.masabi.com\/es\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.masabi.com\/es\/wp-json\/wp\/v2\/users\/22"}],"replies":[{"embeddable":true,"href":"https:\/\/www.masabi.com\/es\/wp-json\/wp\/v2\/comments?post=12057"}],"version-history":[{"count":0,"href":"https:\/\/www.masabi.com\/es\/wp-json\/wp\/v2\/posts\/12057\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.masabi.com\/es\/wp-json\/wp\/v2\/media?parent=12057"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.masabi.com\/es\/wp-json\/wp\/v2\/categories?post=12057"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.masabi.com\/es\/wp-json\/wp\/v2\/tags?post=12057"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}