5 ms·
I'm kind of sad that we're using HTTPS as a transport though their use cases make sense. It seems this is intended to exist alongside the existing & new secure
by proaralyst 8y ago
I'm kind of sad that we're using HTTPS as a transport though their use cases make sense. It seems this is intended to exist alongside the existing & new secure protocols? Is it foreseen that this will only be used by web apps?
- dharmab 8y agoYes. No. See also DNS over QUIC.
- groovybits 8y agoSomewhat tangential: HTTP/3, which will also be using QUIC https://tools.ietf.org/html/draft-ietf-quic-http-13 https://tools.ietf.org/html/draft-ietf-quic-http-13
- judge2020 8y agoIsn't HTTP/3 just the name for IETF's QUIC? https://news.ycombinator.com/item?id=18427795 https://news.ycombinator.com/item?id=18427795
- dharmab 8y agoThere's QUIC (protocol) and HTTP/3 (HTTP over QUIC). DNS over QUIC uses the first but not the second.
- groovybits 8y agoQUIC (Quick UDP Internet Connections) is a protocol derived from Google's Speedy project. Another protocol would use QUIC to initiate a handshake between server and client. The cool thing is that it only takes one UDP packet to do what TCP does in the typical SYN/SYN-ACK/ACK.
- jimktrains2 8y agoWell, it's not quite exactly the same thing as the 3-way handshake over a single packet. The 3-way handshake ensures that both ends are able to send traffic to their counterpart. Just because i receive a packet doesn't mean I can send one back.
- bluejekyll 8y agoPerhaps a better way to phrase it, is that the 3way handshake does not need to be completed before sending data.
- dcbadacd 8y agoCouldn't this mean massive amplification attacks?
- jgrahamc 8y agoHTTPS isn't only used for webapps. It's widely used for APIs from mobile phone apps (for example). There are also a ton of libraries etc. for handling HTTP and HTTPS making it easy to adopt.