4 ms·
You trust browser vendors pretty hard already since you're routing ALL of your information through them. > probably be able to compromise the ENTIRE web I don
by bfred_it 9y ago
You trust browser vendors pretty hard already since you're routing ALL of your information through them.
> probably be able to compromise the ENTIRE web
I don't buy it. HTTPS reduces what you can do, not increase it. At most it can give a false sense of security but that's about it.
- cocktailpeanuts 9y ago> You trust browser vendors pretty hard already since you're routing ALL of your information through them. Yes, but just because we already do doesn't mean I shouldn't have rights to hate the reality even more. > I don't buy it. HTTPS reduces what you can do, not increase it. At most it can give a false sense of security but that's about it. That's true. I wasn't arguing about what HTTPS can or cannot do, I was arguing about how HTTPS is centralized. No matter how safe a piece of technology is, the attack vector increases the more it gets centralized. I've never been a fan of the reality we live in--where the core protocol is elegantly decentralized yet we still end up with a centralized trust to be safe. I think it's ridiculous that every existing website in the world needs to have a certificate authorized by a small number of entities. Also another point I'm making is that people look at this move by Google and think "wow Google is really advancing the web!" but don't see their motivation behind it. 1. Google owns the "open web". 2. Enforcing HTTPS will make sure things become more centralized, which will make it easier for google to keep controlling the "open web". 3. Google profits. I know this sounds like a conspiracy theory, but I'm just stating the facts. I can't think of any other scenario when HTTPS gets more and more traction. It's important to distinguish this problem from the actual problem HTTPS is solving, because I do think HTTPS itself is great.