3 ms·
I don't see why you're opposing HTTPS everywhere and SNI, HTTP already had the Host header so it is not a new information leak. It's pretty much mandatory if y
by ajnin 2y ago
I don't see why you're opposing HTTPS everywhere and SNI, HTTP already had the Host header so it is not a new information leak.
It's pretty much mandatory if you intend to serve multiple domains with different certificates from the same host/proxy, which seems like a very very common use case, and there is no alternative to this right now.
- 1oooqooq 2y agoI don't see how you think NSI doesn't nullify https everywhere. "we need MitM for performance". listen to yourself. if some optimization breaks security, you do not optimize.
- d-z-m 2y ago> I don't see how you think NSI doesn't nullify https everywhere. It doesn't. SNI doesn't leak the URL being accessed, or anything that isn't encoded in the hostame.