4 ms·
It's a power grab in tge same sense as when people got outraged that everything on HTTP suddenly had to have PKI and x509 certificates. While x509 is shit, ASN1
by awaythrow999 2y ago
It's a power grab in tge same sense as when people got outraged that everything on HTTP suddenly had to have PKI and x509 certificates. While x509 is shit, ASN1 an outdated mess, nobody would today argue that TLS is bad.
- akira2501 2y ago> HTTP suddenly had to have PKI and x509 certificates. Was that because the government mandated that outcome?
- immibis 2y agoThat was definitely a power grab. Suddenly CAs had all the power. The ONLY reason we ever accepted a browser-mandated transition to TLS is that Let's Encrypt started existing. Without Let's Encrypt, this would have the effect of requiring every website operator to pay money to a CA, even with full self-hosting. When Let's Encrypt eventually stops behaving in an altruistic fashion, we'll stop doing near-mandatory TLS.
- sidewndr46 2y agoI would argue that with mandated TLS, there is no such thing as "full self-hosting" any longer if you want to be part of the web. Everyone is beholden to a CA somehow
- superkuh 2y agoEveryone's home internet connection now is very fast. They are very capable of hosting a static website of files in folders from home as a human person without CAs being involved. And it's much safer than, say, running Chrome w/javascript on and visiting a random website.
- immibis 2y agoExcept they aren't fully capable, because it's considered insecure and certain features are disabled, and all options to bypass this was deliberately made extremely difficult to bypass. It would be even worse if Mozilla's original plan had succeeded - making TLS completely mandatory on the Internet, so that http URLs would only be accepted for localhost and RFC1918 IP addresses.
- superkuh 2y agoYes, people stuck using a corporate browser might have trouble accessing non-corporate websites because of those browser's loses of capability. It sucks. HTTP webservers are fully capable but realistically every human person should do HTTP+HTTPS for the best of both worlds. Regardless, for HTTP there's an entire 'year 2000's web' worth of people out there using browsers that can access the non-corporate web. As the corporate web diverges with things like stateful HTTP extensions, UDP HTTP, and CA TLS only implementations (if not spec) there's no need to switch to a niche protocol like Gemini. Just making a normal website on the web is enough to bring back the old small web environment. As a human person not operating under a profit motive and just doing things for kicks this is just fine. A silver lining like how usenet is actually good again now that most people don't get it from their ISP.
- immibis 2y agoCorporate browsers such as (checks notes) Firefox and all of its forks.
- 2y ago
- mike_hock 2y agoASN1 >>> some "readable" "plain text" crap. Though ASN1 inside base64, now that's hilarious!
- superkuh 2y agoTLS is not bad, but CA TLS is for the vast majority of human persons on the internet. It makes things very fragile and only last a couple years max without constant mantainence. This is okay for commerce and institutions but for human websites it is devestating. Human persons just don't have the same use cases or threat models as a megacorp and cargo culting megacorp style solutions to everyone is bad.
- foobiekr 2y agoThe threat model of plain http is about the user (and injected content) and not the server. Plain http is a threat to users. Has it really been so many years since people used to do tcp injections and walk around coffee shops or whatever returning results faster than the internet server and injecting goatse? You guys have forgotten who tls protects.
- superkuh 2y agoNope, you've just applied your application model of the web to the web as a whole. Most websites are not actually applications and the risk of "injected content" to people with javascript turned off is very, very low. The risk comes from the absolutely bonkers corporate/institutional use cases of automatically executing all random unverified programs sent to you. When you remove this crazy use case suddenly all the problems (and bonkers requirements) go away. Seeing a goatse is not the end of the world and actual MITM injection attacks like you describe are rather rare now. I miss when wifi use to be open and that issue mattered.
- foobiekr 2y agoThe average user does not have JavaScript turned off. Plain http sites are a risk to their users.