3 ms·
Could you explain what problem you're trying to demonstrate here? What's the bad thing?
by tene 6y ago
Could you explain what problem you're trying to demonstrate here? What's the bad thing?
- a1369209993 6y agoIt's no longer possible to fetch some things over HTTP at all, because the server responds, not with the content requested, but with a demand to use a different, more complicated protocol.
- jchw 6y agoThe justification for having most internet services adopt this standardized, patent-unencumbered protocol with multiple free and open source implementations is well documented; it’s become a best practice for many reasons. Your reasoning for not using one of the aforementioned implementations isn’t documented and is hard to guess. On the other hand, on a typical secured WiFi connection over TCP over an Ethernet connection, like 10 times more complicated stuff is going on in protocols and the software stack. It’s not as if we went from bit banging HTTP directly down an Ethernet cable to a hopelessly complex stack of software; we just added another element of complexity at the application layer in exchange for real security and privacy benefits. Example.com doesn’t need it but it has become a best practice for good reason so it is used on most of the net even when not strictly necessary. Enforcing HTTPS is a best practice because an absurdly overwhelming majority of user agents, like 4 or 5 nines of them, support HTTPS and the redirect ensures they use HTTPS and makes downgrade attacks a little more involved.
- elendee 6y agoFrom an engineering perspective https makes all the sense in the world, but the *pain-point I think they're getting at is that http/s is basically user-facing as well, and it is now both more difficult to set up and maintain, and less semantic, for hundreds of millions of people. Over the past decade I've helped maybe 100 small businesses set up internet presence, and I promise you none of them understand https or set it up correctly at first, despite often paying for it from hosting providers like Godaddy. This isn't the fault of the engineers behind implementing it; it was necessary of course. But if the web were a perfect authoritarian regime we could have just saved us all the headache and dropped http altogether, thus avoiding this bureaucratic protocol redirecting mess. I would be very interested to read about why that was not done actually. (I'm sure there were reasons)