4 ms·
I'm completely cool with it. Modern equipment can handle plenty of SSL traffic, and SSL-by-default will protect me (and you) from lazy developers. The real que
by brandon 14y ago
I'm completely cool with it. Modern equipment can handle plenty of SSL traffic, and SSL-by-default will protect me (and you) from lazy developers.
The real question is whether or not this will proliferate and to what extent.
- zobzu 14y agoYeah but you've to pay for SSL certs that works in everyones browser without a fat "DONT GO TO THIS EVIL WEBSITE OMGOMG SELFSIGNED TERRORIST" Meaning you'd have to pay a tax to put your site on the net when everyone only uses SPDY.
- caf 14y agoYou haven't had to pay for SSL certs for several years now - for example http://www.startssl.com/ http://www.startssl.com/.
- wmf 14y agoThere's been some discussion that you could run SPDY with a self-signed cert and it just wouldn't show the lock. People need to make their opinions on this topic known to Google and Mozilla before the security model is finalized.
- ComputerGuru 14y agoDo you have any info on that? Links, references, mailing list messages, anything? That's super interesting and honestly, the way it should be. HTTPS w/out certificate verification is STILL more secure than HTTP and it should be treated as such - not as the black sheep that it currently is.
- wmf 14y agohttps://groups.google.com/forum/#!topic/spdy-dev/R3Pt4NE2bjc https://groups.google.com/forum/#!topic/spdy-dev/R3Pt4NE2bjc http://thread.gmane.org/gmane.ietf.http-wg/9960/focus=10001 http://thread.gmane.org/gmane.ietf.http-wg/9960/focus=10001 Like I said, they're just discussions and currently the tide is against us.