3 ms·
This will likely never be the case due to how HTTPS actually works. As someone else stated, HTTPs is HTTP + TLS. The "s" in HTTPS is for "secure", and TLS prov
by vtlynch 10y ago
This will likely never be the case due to how HTTPS actually works. As someone else stated, HTTPs is HTTP + TLS.
The "s" in HTTPS is for "secure", and TLS provides that security.
TLS is a evolving standard which is updated over time to add new features when necessary. When HTTPS is negotiated, it can seamlessly choose which version of TLS to use, based off what the client and server want to use.
So, HTTPS will never die due to lack of features. A new version of TLS will just be approved and deployed, and newer devices can use that while older devices can get by on an older version of TLS.
TLS is the successor to SSL. They are backwards compatible, so devices that support TLS also support SSL. The full version history, from newest to oldest, is: TLS 1.2, TLS 1.1, TLS 1.0, SSL 3, SSL 2. In reality, very few servers still use SSL 3 or SSL 2, due to known weaknesses, but colloquially, all the versions are just called "SSL".
TLS 1.3 is underway and will shortly be ready for primetime. Firefox and Cloudflare have already written some implementations based on the draft spec (sorta how routers will implemented the newest 802.11 standards before they are 100% official).
- profmonocle 10y agoPlus, even if we did decide to fully replace TLS, nothing would necessarily need to happen with certificates. We call them "SSL certificates", but the certificate standard - X.509 - actually predates SSLv1 by several years. A TLS alternative/replacement could adopt the X.509 standard as its certificate format and automatically work with the existing CA system.