3 ms·
> It's about cost, too. HTTP can be cached very efficiently, but FTP not at all. It's ironic that you mention cost and caching but lot of services used for sof
by mato 9y ago
> It's about cost, too. HTTP can be cached very efficiently, but FTP not at all.
It's ironic that you mention cost and caching but lot of services used for software distribution of one kind of another (e.g. Github releases) are following the "HTTPS everywhere" mantra and HTTPS can't be cached anywhere other than at the client.
- calpaterson 9y agoGithub probably trust their CDN with their TLS key. For Debian, packages are secured by PGP in combination with checksums so it's not relevant for them. The debian repos are often HTTP only.
- mschuster91 9y ago> and HTTPS can't be cached anywhere other than at the client. No. Nexus for example can certainly cache apt, as well as Squid can do if you provision it with a certificate that's trusted by the client. Also, Cloudflare supports HTTPS caching if you supply them with the certificate, and if you pay them enough and host some special server that handles the initial crypto handshake you don't even have to hand over your cert/privkey to them (e.g. required by law for banks, healthcare stuff etc)
- mato 9y agoTo clarify; what I meant is that HTTPS can't be cached by third parties. If I want to run a local cache of anything served over HTTP it's as easy as spinning up a Squid instance. With resources served over HTTPS I can't do that.