4 ms·
What I don't get is why the industry has decided to force encryption with HTTP/2? The spec does not require TLS however almost every single major browser only s
by ashray 10y ago
What I don't get is why the industry has decided to force encryption with HTTP/2? The spec does not require TLS however almost every single major browser only supports HTTP/2 with TLS.
Is this a push to make the internet more secure by design or is there some other reason behind this?
What's the speed difference between HTTP/2 and HTTP/1.1 without TLS? I'm sure this is hard to test because of lack of client support.
It is not always trivial to move large legacy projects to secure connections (especially because any resource, even an image, being loaded from an insecure endpoint results in a warning) so the result is now:
- Support TLS first
- Then implement HTTP/2
Consumers will not be able to take advantage of the better HTTP/2 performance without big changes to websites to first support TLS on the server end. Why?
- mholt 10y ago> What I don't get is why the industry has decided to force encryption with HTTP/2? For reliability and success of the protocol. "Reasons for choosing TLS-only include respect for user's privacy and early measurements showing that the new protocols have a higher success rate when done with TLS. This is because of the widespread assumption that anything that goes over port 80 is HTTP 1.1, which makes some middle-boxes interfere with or destroy traffic when any other protocols are used on that port." (Source: http://http2-explained.haxx.se/content/en/part5.html http://http2-explained.haxx.se/content/en/part5.html) Believe me, TLS is very much necessary in practice here.
- halomru 10y ago>This is because of the widespread assumption that anything that goes over port 80 is HTTP 1.1, which makes some middle-boxes interfere with or destroy traffic when any other protocols are used on that port. I'm not convinced that's a real problem once traffic leaves your servers/CDN. In practice I have seen lots of protocols use port 80, since 80 is the port that's most likely to be unrestricted on even the strictest corporate firewalls.
- noselasd 10y agoIt's a real problem. There are plenty of middle boxes around either at ISPs/cell operators or in residential gateways/modems that interfers on port 80.
- danudey 10y agoWe make mobile games for iOS and Android, and we've mostly switched to HTTPS because of people injecting garbage (ads, mostly) into our content.
- deleted 10y ago[deleted]
- haimez 10y agoBecause the protocol is now significantly more complex that HTTP 1.X and intermediate network services (proxies, etc) would not play well with a unencrypted stream. TLS guarantees that the intermediaries are either fully terminating the client connection and proxying to the server in whatever protocol it supports, or not manipulating the stream at all because it's unable to know the contents therein.
- jamra 10y agoI can't speak on behalf of the internet, but I believe that since HTTP/2 is faster than HTTP/1, a decision was made to force TLS for the sake of privacy. I remember watching a video of some Go developers writing an HTTP/2 client and one of them mentioned that there was an agreement to never accept non encrypted connections.
- feld 10y agoThe requirement for HTTPS everywhere is growing on me, especially after recent papers indicating that traffic is altered even on backbone provider networks.
- mtgx 10y agoWithout it we'd certainly see much more aggressive ad injection from wireless carriers.
- halomru 10y agoThat's simply to give web developers another incentive to use TLS. There is no real technical reason beyond that. >any resource, even an image, being loaded from an insecure endpoint results in a warning By nessesity, unsecured resources undermine TLS's integrity guarantees. An unsecured image on my bank's website would mean that anyone who MitMs my connection can swap that image to show a message that appears to be from my bank. The internet is no longer the trustworthy place it was in the eighties. HTTP2 is one attempt to make developers catch up with ye that.
- ashray 10y agoI agree with you 100%. What I don't get is the tradeoff that happens in this case for sites that do not necessarily need to be secure by design (what about a news site that has no login/etc or a blog?). Should all information on the web be encrypted by default? Should all those sites not benefit from the speed improvements that HTTP/2 offers? It seems unusual to couple HTTP/2 with TLS, again, it's not the spec that does this but the vendors who are doing this. The bigwigs of the industry will throw tons of developer resources at converting everything to TLS (haven't they already for the most part?) and then deploying HTTP/2. They already throw tons of money at being the fastest out there. I find it interesting (worrying?) that while a spec does not specifically enforce a requirement, large browser vendors have enforced it and created an imperative for pretty much everyone to comply if they want the benefits of the new protocol.
- mikeash 10y agoShould J Random Hacker be able to alter your news feed to feed you fake information? I think one reason they insist on TLS is because the need for privacy and integrity is a lot bigger than most people realize, and historically server folks have not reliably made the right choice.
- ashray 10y agoNo, of course not. What would be the economic incentive towards carrying out a sufficiently complex MITM attack on a blog or a newsfeed? In my experience the times that I've had users complain about "injected" information or weird ads, it's usually come from malware that resides ON their system. There's no MITM required for this. The injection happens client side through a browser plugin or some other resource that gets loaded up along with the page. TLS wouldn't fix this in any way as far as I am aware.
- mtgx 10y ago> Is this a push to make the internet more secure by design Yes? I thought that was obvious. Google is even giving higher ranking to HTTPS sites now and even showing HTTPS versions of the site by default on Google, I believe. If I'm not mistaken Apple is also pretty much forcing all app developers to use encrypted TLS connections for their apps (although there may be some exceptions).
- srj 10y agoThe HTTP/2 protocol negotiation happens with ALPN, which is a part of TLS. It's possible to simply not negotiate or find another means, but in practice there are many proxies on the Internet that assume all port 80 traffic is HTTP/1.1 and will break an HTTP/2 connection.
- kpcyrd 10y ago> It is not always trivial to move large legacy projects to secure connections Actually, it is: https://www.w3.org/TR/upgrade-insecure-requests/ https://www.w3.org/TR/upgrade-insecure-requests/