4 ms·
HTTP/2 is a big step forward, but I wish web servers and HTTP clients supported HTTP/2 over TCP (h2c), TLS encryption is useless for internal microservices.
by KAdot 10y ago
HTTP/2 is a big step forward, but I wish web servers and HTTP clients supported HTTP/2 over TCP (h2c), TLS encryption is useless for internal microservices.
- mattnewton 10y agoIsn't that thinking what got google tapped by the NSA in those infamous prism slides? (Honest question, I don't know if there are other solutions)
- hedora 10y agoYes, and it wasn't just Google. Client or even frontend https wouldn't have solved the problem in most cases (it is necessary but not sufficient). The database (or key value store, etc) replication stream is a prime target, as are any backend protocols that let edge data center storage proxy internal requests for core data centers.
- RandomInteger4 10y agoCan you elaborate?
- Matthias247 10y agoI would interpret it as: a) HTTP/2 is often only supported in encrypted mode (h2). E.g. all browsers only supported the encrypted version, and lots of server side libraries then went the same route. b) encryption might not be needed, if the services already communicate to each other in a secure environment (e.g. are located on the same host, run in an encrypted/secure network, etc.) In such environments the additonal encryption on HTTP level will only show it's downsides, like lower performance and additional deployment/maintainence concerns (certificate deployments, etc.). I'm no expert in cloud/microservice environments, so I don't know that the usual configuration is there. But in general I would agree that there are some environments where HTTPS is simply not needed, like using it for localhost IPC on trusted systems.
- bastawhiz 10y ago> TLS encryption is useless for internal microservices This is very much untrue, especially if you have multiple datacenters, run in the cloud, or operate out of a colo facility.
- vlowther 10y agoFunny, TLS + internal CA + multiple roots is how my microservices determine who is allowed to talk to whom.
- morecoffee 10y agoYou probably don't want clear text. A number of major ISPs (and proxies) poorly implement HTTP. They are either buggy or intentionally modify your connection. There was a blogpost by Youtube a while back about how turning on SSL actually increased the speed and reliability of video serving.