4 ms·
One of greatest things about the Web is how easy it is to write HTTP clients and servers. I see why HTTPS everywhere would be helpful, but I also think it woul
by panic 9y ago
One of greatest things about the Web is how easy it is to write HTTP clients and servers. I see why HTTPS everywhere would be helpful, but I also think it would be a shame to lose this simplicity. Has there been any thought put toward simpler alternatives to HTTP+TLS?
- CydeWeys 9y agoThat's way outside my area of expertise. I don't think HTTPS is that bad anymore, not now that certificates are easy to obtain. What are your biggest pain points? More broadly, I think it's worth incurring some inconvenience for the sake of security. Go too far in the other direction and you end up like Equifax.
- AndyMcConachie 9y agoYou may want to read up on DANE. https://tools.ietf.org/html/rfc6698 https://tools.ietf.org/html/rfc6698 Not really an alternative to HTTP+TLS, but possibly another way of doing it depending on how it's implemented.
- jopsen 9y agoThink of all the time we heard about people stealing passwords from HTTP over wifi networks.. Forcing security at multiple levels and making HTTPS easier is the way forward.
- hannob 9y ago> Has there been any thought put toward simpler alternatives to HTTP+TLS? Well, many people think that current TLS is too complicated and in part that discussion led to TLS 1.3. While I'm still not entirely happy with the complexity, it is far less complex than TLS 1.2. TLS 1.3 removes a lot of the options that 1.2 had.
- electrum 9y agoIt's easy to write a simple HTTP client or server that works for the happy path of the exact software you tested it with. Writing one that follows the RFCs and doesn't allow various security holes when the RFCs are violated is much harder. HTTP is not a simple protocol.