4 ms·
To be fair the real problem is not mandatory TLS, it’s mandatory WebPKI certs: self-signed certs are not a problem in a local docker container, and is not worse
by navaati 6y ago
To be fair the real problem is not mandatory TLS, it’s mandatory WebPKI certs: self-signed certs are not a problem in a local docker container, and is not worse than unencrypted.
- cma 6y agoIsn't there a performance burden?
- OptionX 6y agoSupposedly not (vs TCP/TLS), at least not in the Google implementation (haven't read anything about the IETF version). And with 0-RTT, when it comes out, you gain some performance back anyway by not having to re-handshake on drops.
- cma 6y agoThe comparison would be against TCP with no TLS, since the issue was mandatory encryption.
- loeg 6y agoSome, but maybe less than you think if you're using OpenSSL and a computer less than ten years old (AES-NI and maybe PCLMULQDQ for GCM). Often something else (NIC, network) will be the bottleneck.
- coddle-hark 6y agoYou still need to add those certs to a bunch of different places (browsers use their own certificate stores). More importantly, I don’t think it’s a good idea to teach people to add self signed certs to their certificate stores willy-nilly. Seems like a good way to get pwned.
- a1369209993 6y agoWell, there are other problems (even requiring encryption at all means some low-power clients can't use it because they lack the processing power), but X.509/WebPKI is the main one, followed by ciphersuite proliferation requiring dozens of times as much audited cryptographic code.