3 ms·
SPDY does not technically require TLS, but It's the Right Thing To Do [tm]. According to Mike Belshe, there are two reasons that SPDY was designed to use TLS. T
by mdwelsh 14y ago
SPDY does not technically require TLS, but It's the Right Thing To Do [tm]. According to Mike Belshe, there are two reasons that SPDY was designed to use TLS. The first was pragmatic: Middleboxes on the Internet wouldn't be able to pass through non-HTTP traffic, so unless a different port was used, the only way to punch through the various proxy layers was to use end-to-end security. But the other reason is just as important: It's 2012, folks. It seems insane that most Web traffic goes in the clear. Browsers are fully capable of doing the SSL handshake without incurring a major performance cost - even on mobile devices. Finally, we may not get another chance to change the web protocol stack for another 15 years, so it's best to get it right now.