4 ms·
Probably because very little innovation happens to any long-standing protocol until it becomes a primary business concern. Almost every business relies on Open
by j42 11y ago
Probably because very little innovation happens to any long-standing protocol until it becomes a primary business concern.
Almost every business relies on OpenSSL or some equivalent, but how many actually learn enough about SSL to contribute back to the codebase? Not many, because despite the need there's little acclaim or funding to be had pursuing things that won't make direct revenues, regardless of their importance.
Protocols like this generally don't get updated until it becomes a matter of necessity -- either by public awareness (we're far from that point) or someone designing the "next big thing" needs an un-implemented feature and contributes.
- cm2187 11y agoOne can argue that spam and phishing IS a business concern. Many of the major data breaches involved a phishing attack. Fixing smtp should be as important if not more than upgrading http 1.1.
- j42 11y agoOh it absolutely is, and I'm on your side. My point though, is that it's always a "secondary" or "tertiary" business concern... a point emboldened by the number and frequency of data breaches -- always followed of course, by the email newsletter follow-up & mea culpa. "We care about the security of your data, we swear. We regret to inform you that ..." Sadly things are not always as they should be, friend...